House seal

House · Hearing transcript

State and Local Cybersecurity: Threats, Federal Partnership, Resilience

Tuesday, May 19, 2026

Summary

  • Andrew Ogles pushed reauthorization of the expiring State and Local Cybersecurity Grant Program through the Pillar Act before the September deadline.
  • Kristin Darby (Chief Information Officer, State of Tennessee) said Tennessee secured 89,684 endpoints and trained 21,000 local employees using grant funds.
  • Carlos Gimenez pressed Colin Ahern (Director of Security and Intelligence, State of New York) on adversary manpower and AI-driven defense automation.
  • Delia Ramirez blamed administration CISA cuts for weakening election security while Andrew Ogles focused on grant flexibility and state-led solutions.
  • Without reauthorization by September, rural communities lose critical protections as AI-enabled attacks accelerate against hospitals, schools and water utilities nationwide.

Morning digest

Get hearings like this in your inbox

Free weekday email. Unsubscribe anytime.

Hearing Details

Witnesses

Members Who Spoke

View on Congress.gov

Transcript

Rep. Ogles (TN-5)12:09 – 17:30

The Committee on Homeland Security, Subcommittee on Cybersecurity and Infrastructure Protection will come to order. Without objection, the Chair may declare the committee in recess at any point. Congress plays a critical role in assessing whether state and local governments have the resources, strategies, and federal support needed to prepare for the and respond to an increasingly increasingly sophisticated cyber threat environment. Today's hearing examines the current threat landscape, evaluates the effectiveness of federal support programs, and explores how we can strengthen cyber resilience at every level of government. I now recognize myself for five minutes for an opening statement. Good afternoon and thank you all for joining us. I think we have New York, Florida, Virginia and the great state of Tennessee represented, and if I messed that up, you can feel free to correct me. Um, but I truly appreciate you being here. The men and women uh on the front lines of cyber security in our states and local communities for traveling here today. The cyber threat facing America's states, cities and counties today looks nothing like it did just five years ago. Nation, state, actors, ransomware groups and criminal organizations have grown more capable, more persistent, and more willing to target systems that Americans rely on every day. Artificial intelligence is changing this fight in both directions. State and local governments are beginning to use AI to detect threats faster, respond more efficiently, and do more with limited staff. But our adversaries are also using those same capabilities against us, crafting more convincing phishing attacks, finding vulnerabilities faster, and carrying out operations at once that otherwise required specific expertise or specialized. The witnesses with us today have played a key role in helping their states embrace digital transformation and expand access to government services. But with this increased connectivity come the larger attack surface and a greater level of risk. Just last week, a ransom attack on Canvas shut down classes for students and faculty in the middle of final exams. Hospitals have had to r- turn away patients and cancel surgeries. when their systems were held hostage. State agencies have gone off-line for weeks, cutting seniors off for benefits they have earned and depend on. And water utilities have had their control systems probed and in some cases compromised. Each of these incidents has a real human cost, and they are happening more and more often. The core problem is a mismatch that Congress has an obligation to address. State and local governments are expected to defend against the same adversaries our intelligence community tracks, including China, Russia, and Iran. But with budgets and workforces that bear no comparison to what the those nation-states deploy against us, a county government in rural America may not have a single dedicated cyber security professional, and yet that county holds sensitive data on its residents, runs systems that deliver essential services, and sits inside a network of American infrastructure that our adversaries are actively working to disrupt. I know this from per personal experience. Before I came to Congress, I served as County Executive in Tennessee. We had no dedicated cyber security staff and a tight budget. And we still had an obligation protect our residents' data and keep their go keep our government running. This is in part why the testimony we will hear today matters so much to me. To their credit, states have not been waiting for Washington to figure this out. Today we will hear about whole of state cyber security strategies that push resources and expertise down to counties and mean that they cannot otherwise afford. We will hear from about information sharing programs that give smaller jurisdictions access to threat intelligence they could never build on their own. We'll hear about workforce programs developed with universities and community colleges to train the next generation of defenders. These are real solutions and they deserve real support from Congress. But state efforts can only go so far without federal support. Congress recognized that in twenty recognized that in twenty twenty one when we created this state, and local cyber security grant program and put one billion dollars behind it over four years. The premise was simple, a small town faces the same threats as a large city, and a rural county is not exempt from Chinese or Russian cyber actors just because it has a limited IT budget. That program helps communities that could not otherwise help themselves. Unless Congress acts, that program expires this September. We should not let that happen, and we certainly should not let it happen at a moment when the threat is growing ever worse. That is why I am committed to enacting the Pillar Act, which we passed, and we sent to the Senate Homeland Security Committee. Reauthorization alone is not enough. We have four years of program history now, and we owe it to taxpayers to ask whether the money is being spent well, whether the structure is right, and whether the outcomes match the investment. Today is an opportunity to get honest answers from people who have actually run these programs. I look forward to hearing from all of our witnesses, especially Tennessee, and using that we and using that to drive our actions as we go forward. And I'll recognize the ranking member, member, the gentlewoman from Illinois, Miss Ramirez, for five minutes for her opening statement. Meg?

Rep. Ramirez (IL-3)17:30 – 22:19

Thank you, Chairman. Well, good afternoon. I wanna start by expressing my solidarity with the Islamic Center of San Diego. My condolences to the families of Amin Abdullah, Mansour Kasiha, and Nadira Wad. who were murdered in a horrific hatefield attack on the Muslim community. I I wanna say this because it's really important. We have to recommit ourselves to rooting out violence and hatred in all its forms. Since the incident, we've learned that the two suspects espoused hateful views about Muslims, about Islam, Jewish people, LGBTQ plus community, black people, and people across the political spectrum. They also expressed beliefs that white people are being eliminated, echoing the dangerous, white supremacist great replacement theory. I raise these details in our subcommittee because as members of Congress, we have to remember that our words matter. Words matter to six year old Waday Ofayumi of Illinois, who was murdered because of dangerous anti-palestine rhetoric. There are too many examples of children put at risk by reckless misinformation and propaganda that fuels heinous attacks. And we as elected officials have an obligation to hold ourselves to the highest standards, rejecting dehumanizing dehumanizing rhetoric and working to end all forms of bigotry, so that no children, no family, no community around the country has to suffer as a result. In addition to being responsible for our words, today we address our responsibility to address cyber security threats facing our state and local governments. We are facing a rapidly evolving landscape. The administration initiated an unlawful military operation against Iran, a country with a track record of responding to military operations via cyber capabilities. Last month, Anthropic announced a Mithos preview, a highly capable AI model that has proven to be exceptionally effective at identifying vulnerabilities in software and writing, exploiting for them. And in less than six months, state and local governments will administer the midterm elections a target of past foreign interference efforts. While our work should be focused on responding to the rapidly changing cyber landscape and supporting state and local governments to defend against cyber security threats, the administration has been doing the opposite. It's eviscerated the workforce at Cybersecurity Infrastructure Security Agency, leaving us with eleven hundred vacancies. It's eliminated CSA's election security team and defunded the multi-state information sharing analysis center and the election infrastructure information shares, sharing and analysis center, its reassigned cyber security professionals to ICE, and even the FBI cyber security staff have been stretched thin. There are real consequences when the federal government guts the personnel and the resources that we have dedicated to identifying cyber security risk, and mitigating them. And that's why this subcommittee hearing is so important, because state and local governments store significantly personally identifiable information about people in our communities. information about our school children, to those receiving public s- benefits, to even information on our small business owners. Failing to support cyber security efforts at the state and local level puts that information at risk and it actually jeopardizes the privacy of the public. State and local governments have also had the responsibility of administering free, fair, and secure elections. It is the federal government's responsibility to ensure they have the support and the resources to be able to do such this. And thanks to the efforts of Congresswoman Eva Clark, uh the former chair of the subcommittee, the federal government invested over a billion dollars over the last four years in state and local cyber security through state and local cyber security grant programs. But the program issued its final grants in year twenty twenty five. So while I appreciate the efforts of the full and subcommittee chairman to extend this important program, I am concerned that leadership doesn't have a plan to move this bill forward. The officials I've spoken to have articulated frustration that so many of the CISA personnel that they relied on for so many years and trusted no longer work at the agency. And support to the MS ISAC and the EISAC was also eliminated. So if Congress doesn't reauthorize the state and local cyber security grant program, the message will be reinforcing that you are on your own. And I find that to be unacceptable. We have to change course and we need to renew and local cyber security grant program because that is a step in the right direction. I look forward to hearing the witnesses' perspectives on this point in particular. And before I close, chairman, I'd like to submit the following statements for the record. A statement from the Center for Internet Security which houses the MS ISAC.

Rep. Ogles (TN-5)22:20 – 22:20

Go ahead.

Rep. Ramirez (IL-3)22:21 – 22:25

A report from the bipartisan policy center R Street and the Institute for Responsive Government.

Rep. Ogles (TN-5)22:26 – 22:26

This way.

Rep. Ramirez (IL-3)22:27 – 22:32

And the Consortium for School Networking. With that, I yield back to the Chairman. Thank you.

Rep. Ogles (TN-5)22:34 – 24:09

Thank you to the ranking member, Ramirez, and I would like, if I may, to echo her comments. Uh, we can have political, uh, religious, uh, disagreements, but violence is never acceptable. Whether it's the attacks against the President, against members of Congress, individuals in our community, or at the mosque. So with that, we'll take a quick moment of silence. Thank you. Members of the committee are reminded that opening statements may be submitted for the record. I'm pleased to have a distinguished panel of witnesses before us today on this important topic. Pursuant to Committee Rule eight C, I ask our witnesses to please rise and raise their right hands. Do you solemnly swear that the testimony that you will give before the Committee on Homeland Security of the United States or the House of Representatives will be the truth, the whole truth and nothing but the truth, so help you God. Let the record reflect that the witnesses have answered in the affir affirmative, thank you and please be seated. I would like to now formally introduce our witnesses. Miss Kristen Darby is the Chief Information Officer from the fantastic and amazing and great state of Tennessee. I may have a little bias there, where she oversees technology strategy, innovation and solutions for government services. She previously served as the CIO at various healthcare companies and has over twenty-five years of experience in the public sector, health care, finance, operations, biotech, cyber security, and insurance. Mister Collin

Colin Ahern (Witness)24:13 – 24:13

Ahern, sir.

Rep. Ogles (TN-5)24:14 – 25:30

Ahern, thank you, sir. He's the newly appointed Director of Security and Intelligence for the State of New York where he coordinates the state's security assets on national security and intelligence matters. He most recently served as the first chief cyber officer held cyber leadership roles for New York City and served in the US Army. Thank you for your service, sir. Mister Warren Sponholz is the Chief Information Officer for the State of Florida, where he leads the Florida Digital Service in moder- modernizing IT infrastructure and strengthening and strengthening the state's cyber security defenses. He previously served as Deputy Chief Information Security Officer at Florida, Digital Service as CIO of the Florida Department of Environmental Protection, and as a United States Marine. Also, sir, thank you for your service. Mister Samir Jain is Vice President of Policy at the Center for Democracy and Technology where he leads policy advocacy and guides the organization's policy agenda and strategy. Mister Jain helped shape national cyber security s strategy and coordinate cyber policy in various positions in the Obama administration, and he was a partner at two international law firms. I thank each of our distinguished witnesses for being here today. I now recognize Miss Darby. from five minutes to summarize her opening statement.

Kristin Darby (Witness)25:33 – 30:39

Chairman Ogles, Ranking Member Ramirez, and the distinguished members of the subcommittee, thank you for the opportunity to testify today on behalf of the great state of Tennessee. I'm Kristen Darby and I serve as Chief Information Officer for the State of Tennessee and oversee strategic technology solutions. The state's centralized information technology organization supporting twenty-one executive branch agencies and approximately forty-five thousand state employees. I also serve as the co-chair of Tennessee's Artificial Intelligence Council and the state's Cybersecurity Council. Cybersecurity is no longer simply a technology issue. It's a matter of public safety, economic safety, and national defense. State and local governments operate critical systems, that citizens rely on every day, including emergency services, schools, utilities, courts, and public infrastructure. Those systems are increasingly targeted by criminal organizations and nation-state actors. In Tennessee, we are seeing rapid growth of AI-enabled attacks, ransomware activity, and exploitation of cloud and identity systems. The pace of these threats continues to accelerate. At the same time, many local governments across our state have little or no dedicated cybersecurity staff. This creates a dangerous imbalance between highly sophisticated attackers and severely resource constrained defenders. We are also entering a new phase of cybersecurity risks, driven by advanced large language models and artificial intelligence. Emerging capabilities are accelerating vulnerability discovery and compressing the time frame between identification, exploitation, and remediation. Tennessee has responded with a whole of state cyber security approach focused on partnership, coordination, and scalable shared services under the leadership of our state CISO, Curtis Klan. Through our statewide engagement efforts, we have engaged more than fifteen hundred organizations, reached over three thousand public sector points of contact, and achieved number one ranking in the US with the nationwide cyber security review completions in both twenty twenty four and twenty twenty five. Most importantly, we are seeing measurable results. Organizations that participated consistently over three years demonstrated a nineteen point two percent increase in overall cyber security maturity. Through the state and local cyber security grant program, Tennessee has secured eighty-nine thousand six hundred and eighty-four endpoints across local government. We've trained more than twenty-one thousand local government employees, and we've expanded access to endpoint detection, cyber security training, firewalls, disaster recovery capabilities, and managed services. Many of these local governments simply could not deploy or sustain these capabilities on their own. The grant program has also strengthened trust, communication, and overall coordination between state and local government in ways that continue benefiting Tennessee well beyond individual grant cycles. However, the demand for cyber security support far exceeds the current funding levels. While Tennessee received approximately twenty-one million dollars of federal funding across four grant cycles, we could have effectively utilized several times that amount to address identified needs across our local communities. Without continued funding, local governments will lose access to critical cyber security services. managed protections will disappear. And the momentum we have built through the whole of state approach will slow at precisely the wrong time. Cyber adversaries are not slowing down, and neither can we. Based on Tennessee's experience, I respectfully encourage C- Congress to consider continued appropriated funding for the state and local cyber security grant program lower and stabilized cost share requirements, improving real-time threat intelligence sharing, and establishing a rapid response funding mechanism that allows states to react quickly to emerging threats and zero-day vulnerabilities. The scale, speed, and complexity of today's threat environment requires the ability to respond at the pace of emerging threats. Thank you for the opportunity to testify

Rep. Ogles (TN-5)30:42 – 30:47

Thank you, Miss Darby, and I'll recognize Mr. Ahern for five minutes to summarize his opening statement.

Colin Ahern (Witness)30:47 – 35:37

Chairman Ogles, Ranking Member Ramirez, Chairman Garbarino, Ranking Member Thompson, and distinguished members of the subcommittee, thank you for the opportunity to testify today. I am Colin Ahern, New York's Director of Security and Intelligence. I want to thank Chairman Ogles for sponsoring the Pillar Act, Ranking Member Ramirez for the critical perspective she has brought to this subcommittee and Chairman Garbarino and Ranking Member Thompson for their focused on state and local cyber readiness. Our states are on the front lines of multiple cyber conflicts, yet we are being asked to manage nation-state risks while our federal partners step back. The coming expiration of the state and local cyber security grant program, the cyber security and infrastructure security agency workforce shrunk by a third with no senate confirmed director and the cancellation of multi-state information sharing and analysis center funding are dismantling tools that keep our communities safe. We are at a critical juncture. Artificial intelligence continues to collapse the technical barriers that once separated nation-state capability from everyone else. New tools are compressing the time of vulnerability attack to exploitation from weeks to hours. And these capabilities will soon be present in freely available open weight models including from China. The window to harden our defenses is not years, it is months. To prepare for today's and tomorrow's risks, Governor Hochul last year signed the responsible artificial intelligence and safety act, one of the country's first state-level safety frameworks for frontier artificial intelligence models. However, we can only succeed together. Adversary nation-states continue pre-positioning inside critical infrastructure stealing our intellectual property, perpetuating hybrid attacks, all while sheltering the ransomware crews that assail our communities every day. These threats are converging, the same criminal cryptocurrency infrastructure that drives billions of dollars in fraud, also funds ransomware, helps bad actors evade sanctions, and lets anyone rent capabilities from professional cyber criminals. We are leaving our communities to fend for themselves against the world's most sophisticated digital adversaries. Federal action against that infrastructure and those adversaries reaches where state defenders in the private sector cannot. We need more of it, and our defense depends on it. New York is a national leader in cyber. Under Governor Hochul's leadership, we have built a whole of state model. consolidated intelligence and security leadership, the nation's most robust state-level cyber security operations center, mandatory municipal cyber incident reporting, and critical cyber defense shared services. Our shared services protect over one hundred thousand county and local government computers in an operations center staffed by nearly sixty civil servants and six members of our National Guard. And by leveraging the state's purchasing power and economies of scale, the state is saving county and local governments over nineteen million dollars a year in providing cyber-sophisticated tools that localities, frequent targets for cyber-attacks, could not employ on their own. New York has also invested an additional seven point four million dollars in expanding the New York State Police Cyber Analysis Units, Computer Crimes Unit, and Internet Crimes Against Children Center. New York is committed to evolving our cyber defenses as threats evolve so that we can remain an effective partner to the federal government and the private sector. My written testimony contains six recommendations. I would like to highlight two. First, reauthorize and fully fund the state and local cyber security grant program, which is the single most consequential investment in the cyber protection of state and local governments in this country. In New York, this program is currently delivering over one hundred and twelve thousand multifactor authentication hard tokens to c- local governments and school districts. Without reauthorization and stable long-term appropriations, the consequences for state and local cyber defense will be immediate and severe. To improve the program's impact, we should also reduce unnecessary burdens and restrictions that currently make it harder for states to deploy enterprise-grade software-as-a-service shared services over multiple years. Second, end two-tiered frontier model AI access. State and local governments protect the energy grid, the drinking water supply, the public health system, and the everyday operations of government. We cannot do that while frontier defensive AI Cyber security is the silent partner of democracy. When the utilities, school districts, and state and local governments that constitute the operational fabric of American life are hollowed out by cyber attacks, the institutions that support our democratic life are hollowed out with them. The recommendations in my testimony are the elements of a single proposition, that the institutions of self-government in this country are worth defending against threats that do not respect state lines or international borders. And that doing so demands a federal government that is a partner to all fifty states. New York is ready to do its part. We want and need the federal government as our partner in this essential work. Thank you. I look forward to your questions.

Rep. Ogles (TN-5)35:38 – 35:42

Thank you, Mr. Erne. I now recognize Mr. Sponholtz for five minutes to summarize his opening statement.

Warren Sponholtz (Witness)35:44 – 40:59

Thank you, Chairman Ogles, Ranking Member Ramirez, members of the subcommittee. Thank you for the privilege to speak before you today. My name is Warren Sponholtz and I serve as the State Chief Information Officer and Director of the Florida Digital Service. I'd just like to start with uh saying that I appreciate the subcommittee's attention on existing and emerging cyber security threats that um that are that face this nation every day. Florida is a large and attractive uh target. It's the third most populous state with roughly twenty-three million residents. Florida also includes nearly five hundred counties and municipalities. It's home to major military commands, premier educational institutions, seaports, airports, and spaceports. But no matter where an attack is focused, our adversaries see us as one target, and our job is to build one coordinated defense. Nation-state activity has become a greater threat for state and local governments. The adversarial use of artificial intelligence is fundamentally changing the speed and scale of cyber threats facing state and local governments. We are rapidly approaching an era of AI-driven vulnerability identification and rapid exploit development. Additionally, China's actions have changed the conversation around critical infrastructure. Campaigns commonly referred as uh Volt Typhoon and Salt Typhoon show that foreign adversaries are not only seeking data, they're positioning themselves in critical sectors in ways that would matter, during a crisis. For Florida, that means we must m- not just monitor for obvious disruption, but also for quiet, long-term um, long-term access that may be designed to remain undetected for years. This is changing how we conduct threat analysis from long-term log retention and alerting thresholds to how we detect quiet persistence before it becomes an operational disruption. The center of that effort and a priority for Governor DeSantis is Florida's Cybersecurity Operations Center or CSOC housed within the Florida Digital Service. The CSOC serves as the state's central threat clearinghouse Monitors threats across the state enterprise, supports incident response, helps agencies and partners move from isolated alerting to coordinated detection and response. Central intelligence, sorry, threat intelligence is central to that program. Florida draws from numerous sources, including federal partners, law enforcement, multi-state coalitions, and cyber security vendors. But intelligence is only useful when it's operationally relevant. Agencies and local partners need timely contextual information that matters to them. The federal government has been an essential partner in this work. Federal intelligence collection and sharing brings national visibility that no individual state can replicate. Florida adds state and local context to that national view. Critical infrastructure is also a major fo- focus of Governor DeSantis's strategy. Florida continues to work with critical infrastructure providers to better understand the investment needed and where systemic risks exist. We used assessment data and the Department of Energy's Cybersecurity Capabili- Capability Maturity Model, or C two M two, to support consistent discussions about risk, maturity, and priority investments. Florida's state-funded local s- government cybersecurity grant program is one of our most important tools for reaching local communities. Rather than simply issuing direct payments, the Florida Digital Service procures cybersecurity capabilities on behalf of participating governments. That model creates economies of scale, decreases procurement friction, reduces bureaucracy, and gives smaller entities access to enterprise-grade solutions. Through Governor DeSantis' leadership and partnership with partnership with the Florida legislature, the program has been funded at thirty million, forty million, and fifteen million dollars over the past three funding cycles. This program provides seven foundational cyber capabilities across a range of solution providers. The federal state and local cybersecurity grant program, or SLCGP, complements Florida's state-funded model by addressing specific needs requested by local entities but are outside the state program. Because of this and the relationships built and helped and helped foster through the program, the SLCGP should receive long-term reauthorization. At the same time, reauthorization must promote practical access for communities that need the program most. Higher unstable match requirements can discourage participation, especially among rural and physically constrained entities. Reimbursement models can also be difficult for smaller communities that can't carry large upfront costs. Federal grant design should make it easier for the most vulnerable communities to participate. In conclusion, Florida has made meaningful process under the leadership of Governor DeSantis. We have built a central cyber security operations capability, expanded incident response support, strengthened state and loc- local collaboration. improved enterprise visibility, and created grant models that help communities obtain protections they could not acquire alone. However, cyber security threats transcend state lines. Continued federal partnership, information sharing, long-term reauthorization of SLCGP will help Florida and other states build a strong connected defense. Mr. Chair, thank you for the oppor- uh opportunity to testify. I look forward to questions.

Rep. Ogles (TN-5)41:00 – 41:04

Thank you, Mr. Sponholz. I now recognize Mr. Jane for five minutes to summarize his opening statement.

Samir Jain (Witness)41:05 – 46:03

Chair Ogles, Ranking Member Ramirez, and distinguished members of the committee, thank you for the opportunity to testify today on the cyber security threats facing state and local governments, and the critical role of the federal government in helping to address them. My name is Samir Jain and I am the Vice President of Policy at the Center for Democracy and Technology, a non-partisan, non-profit organization that has worked for more than three decades to advance civil rights and civil liberties and to foster and promote a more secure and trustworthy, digital ecosystem. State and local governments today are confronting serious cyber security threats across nearly every domain in which they operate, from the critical infrastructure that powers our communities and schools, to the systems that administer our elections, to the public benefit programs that millions of Americans rely on. When these systems are compromised, people can lose access to critical resources and services at the moments they need them most. Recent ransomware and other attacks on cities and local governments have shut down a range of systems, from emergency dispatch to departments of motor vehicles to municipal courts. Each of these episodes meant real people were unable to renew a driver's license, to obtain a birth certificate, or otherwise to engage with local services to which, on which they depend. Cyber intrusions can also mean that people's most sensitive information, social security numbers, financial data, medical information, information about their children, is exposed to criminal actors and foreign adversaries. leading to risks such as identity theft, financial fraud, harassment, and takeover of email and social media accounts. Just recently, for example, as Sheryl has mentioned, the breach of the Canvas uh learning management platform not only disrupted essential learning activities for schools across the country, but exposed sensitive information of over two hundred seventy-five million users, including private messages that may contain deeply personal information. A pernicious knock-on effect to these incidents is the erosion When Americans see a county hospital or their child's school district suffer a major breach, their confidence that the government can serve them effectively and protect their personal information necessarily is shaken. That erosion of trust has consequences far beyond any single incident. It can deter people from enrolling in benefits to which they're entitled, from registering to vote, or from engaging with public institutions. These risks are only heightened as artificial intelligence creates new opportunities for malicious actors to attack and exploit government systems at unprecedented speed and scale. The recent announcements of advanced AI systems with substantial cyber capabilities such as the Mythos preview from Anthropic have made clear that the offensive cyber landscape is poised to change dramatically, and small and under-resourced jurisdictions are likely to be particularly vulnerable to that change. Previously, the federal government has played an indispensable role in helping state, local, tribal, and territorial governments meet these challenges. Through the state and local government grant program, cyber security grant program, and through technical assistance from the cyber security and infra- infrastructure security agency, state and local officials have received targeted funding, threat intelligence, vulnerability assessments, network monitoring tools, and incident response support. The federal government has unique capabilities that no individual state can match, visibility into foreign threat actors and nation-state campaigns, the ability to detect patterns of cyber security activity across jurisdictions, and a hub-and-spoke information sharing architecture, anchored by the multi-state and elections infrastructure information sharing and analysis centers, which has allowed real-time warnings, coordinated defense, and rapid response. But just as a threat environment is poised to accelerate, at an exceptional rate, the federal government has dramatically pulled back. Over the past year, CISA has lost a third of its workforce. Federal funding for the MSI-seq was eliminated. Key grant programs have not been funded or been conditioned in ways that effectively block access to cyber security support. And long-standing institutional knowledge and relationships have been lost. The result is a widening gap between rapidly escalating threats and the diminished federal capacity to help state and local governments meet them. The federal government should act now to restore the funding, the programs, and the institutional capacity that have made federal-state cybersecurity cooperation work. It should reaffirm the federal government's commitment to information sharing with state and local partners, fund CISA, the ISAC ecosystem, and targeted grant programs, and reestablish the free or low-cost services on which thousands of state and local jurisdictions have come to rely. In short, It should renew the sh sense of shared responsibility that has defined constructive federal-state cooperation on cyber security. Thank you again for the opportunity to testify, and I look forward to your questions.

Rep. Ogles (TN-5)46:04 – 46:53

Hey, Mr. Jane, members will be recognized by order of seniority for their five minutes of questions. I now recognize myself for five minutes. Uh, this question would be for Mr. Arby and Mr. Sponholz the integration of AI into cyber security practices is increasingly important as ai enabled attacks can continue to grow in frequency and sophistication. The national association for state cios in deloitte recently published a study that found that all but one security uh cyber security officer are already using or plan to use generative ai to improve cyber security operations. What successes or struggles have you experienced in your state's deployment of ai for cyber security And where do you believe AI can be leveraged to enhance said security? Mr. Arby?

Kristin Darby (Witness)46:55 – 48:14

So, AI has become a integral part of our operational readiness. The areas that we've seen successes are in, um, reducing the, uh, time to react. So the speed of change is most important throughout our environment, and the ability to quickly detect. And so we have seen AI tools um allow us to cro close that response gap in ways that um uh exponentially increase our ability to react and cover uh endpoints throughout not only state government but also local government. In addition to areas of um challenge, I think workforce continues to be an area of challenge, just um developed talent around using ai tools and understanding how the threat landscape is changing, things are moving at a very rapid pace. And so um continuing to understand that w- uh not only the state of Tennessee, but but our partners have the right resources with um the right knowledge around those tool sets and how to best apply them based on the evolving threat landscape has been one of the areas of challenges that we continue to address.

Rep. Ogles (TN-5)48:14 – 48:22

Yes, ma'am, which underscores why the Pillar Act needs to be passed in the Senate and why is this committee will continue to double down on this very issue, Mister Sponholz.

Kristin Darby (Witness)48:22 – 48:23

Absolutely.

Warren Sponholtz (Witness)48:23 – 49:35

Thank you, Mister Chair. Uh, in Florida, we are looking at AI from a cyber security perspective around uh automation of tasks um for cyber security operations. So, uh, moving intelligence into um platforms where we can align with uh vulnerabilities that are in the ecosystem, uh with uh indicators of compromise uh that show up with our telemetry analysis and our cyber analysis. Um that is a very um resource intensive work uh AI can uh not only position so we can be more efficient with our resources but also make it happen much faster and around the clock. So we're excited about that capability around AI. Um more broadly for AI we're also um ensuring that sensitive data is not being uh shared outside um, our our systems and ensure that we have, uh, controls in place to be able to prevent that from happening, and also ensuring that we've got the right kind of c- controls, so we have human in the loop, so no, um, AI actions are taken, uh, uh, for for an agency and an agency action, uh, that aren't in control of a a a human. So we're keeping in mind those, uh, important principles as we, uh, explore the different uses and efficiencies around around AI.

Rep. Ogles (TN-5)49:36 – 50:05

And my next question wouldn't be for any of the witnesses, but I'll start with you, Ms. Darby. when I was County Executive, we had a cyber attack. We were fortunate that we had h had already put in place a contingency plan, so we were able to shut down and boot back up. But when you look at um, you know, cyber security going forward, what do what do you we need to do in partnering with states to make sure the small and rural communities like Murray County when I was Executive aren't left behind, because again of that staffing and talent uh issue that you spoke of, ma'am.

Kristin Darby (Witness)50:06 – 51:40

So we take the responsibility of protecting all of our local communities very seriously in Tennessee, and one of the areas that I do think is important is um participation in the grant program, but also modification of the rules to allow more flexibility. So after I came into this role, um uh a few months in, we had a local community attacked and they had selected one of the services in the grant program, they needed the other service to respond to what the issue was, and based on the grant rules, we were unable to extend that to them. That type of flexibility to allow us to come to the table with any solution to help the local communities in need in the time of an attack is absolutely essential. So I think that area of flexibility is very critical. Um, building the relationships with the state uh the state um IT function, also our National Guard, uh and the many of our other um law enforcement facilities, et cetera. We all have a very coordinated um relationship, and a lot of that was brought through the through the grant program, of building those relationships and the connectivity. The ability to extend um high impact, low touch solutions to those local communities is critical. Because they do not have the resources that a state would have to be able to protect their communities, but their citizens have the same expectations.

Rep. Ogles (TN-5)51:40 – 51:53

Yes, ma'am. My time has expired, and so we'll come back. I think we'll have time for another round of questions, so we'll start with you when I when it's my turn again, but I wanna recognize the ranking member, the gentlewoman from Illinois, Miss Ramirez, for her five minutes of questions.

Rep. Ramirez (IL-3)51:53 – 52:35

Thank you, Chairman. It's certainly a very important conversation, so I look forward to another round. State and local governments operate some of our most critical infrastructure and provide essential public services, you're also maintaining sensitive data on many of our constituents. When nation-state actors or criminal groups get access to that data, our constituents' privacy is put at risk and in danger. So, Mister Jane, can you elaborate on the scale of sensitive information state and local governments have on Americans? And and I think the second part of that question that I I wanna make sure we have for the record, why nation-states and criminal groups might find accessing that data particularly valuable.

Samir Jain (Witness)52:39 – 53:47

Uh, um, thank you, Ranking Member Ramirez. Yeah. I mean, states and local uh governments have some of the most sensitive information about individuals, often even more sensitive than commercial providers have. And crucially, in many cases, this information that people have no choice but to provide to state and local governments to participate. and get them their benefits or to get uh critical services, it's not a voluntary uh relationship necessarily in all cases. And the kind of data we're talking about is everything from medical data, to financial data, to your social security number, to um information about children and um their health conditions. And that data is um, you know, can lead uh loss of that data can lead to harms from identity theft to financial fraud, to impersonation, particularly now, you know, we're talking about a AI, AI is the dangers that AI poses are not only that it enables or makes easier intrusions, but it also enables for the use of this data in more pernicious ways. You can e- more easily draft uh authentic sounding phishing emails to con- uh to conduct fraud,

Rep. Ramirez (IL-3)53:45 – 53:45

Mm.

Samir Jain (Witness)53:46 – 54:11

Yeah. and engage in other kinds of impersonation using AI in ways that you couldn't before. And so um you know all of that is critical and you know foreign actors want that information um sometimes they're criminal in nature and they want the information just to gain money sometimes um particularly some of our adversaries will want that information for counter intelligence type purposes particular if you're talking

Rep. Ramirez (IL-3)54:09 – 54:10

mmm mmm

Samir Jain (Witness)54:11 – 54:14

about individuals who are serving in the military or in the government

Rep. Ramirez (IL-3)54:14 – 54:28

yeah so i think i know the i think you started actually answering my second question but i wanna make sure that i ask it for the record why is it so important that the federal government increased support to state and local governments to better protect our constituents' privacy.

Samir Jain (Witness)54:29 – 54:53

Because right now they're we're we're they they face a real asymmetry in terms of the resources and capabilities of the attackers not only nation state attackers, Mm-hmm. but with the advent of AI the ability of even criminals to have hor- incredibly sophisticated capabilities. And on the other hand, you've got state and local governments that lack a lot of resources and staffing Mm-hmm. in which the government can the federal government can really help

Rep. Ramirez (IL-3)54:53 – 55:30

and i assume that the other three witnesses would agree you would wanna see more federal support for all those reasons thank you well let me just wrap up on a question on election security under this administration CISA has cut its long-standing election security support to state and local election officials while congress has restored funding for CISA's election security programs uh the administration uh does not agree in restoring these funds and CISA does not intend to be the partner to state and local elections that it has been in the past. So, Mister Jane, this question's for you and then I have another question for the rest of the folks here. What is the impact of CSA cutting support for election security?

Samir Jain (Witness)55:31 – 56:10

I think it's quite critical impact for the similar reasons that we're talking about. Election officials, which, you know, include, you know, in many cases just very local jurisdictions that lack a lot of resources or lack staffing, facing, you know, election of uh election systems are um attractive targets for nation states. And um without those kind of security support, um you know the integrity of our elections are potentially at stake. And you know even whatever there's obviously a lot of disagreement around elections and some of the pol- politics around it, but we should all be able to agree that we don't want nation states or other foreign actors interfering in vote counts,

Rep. Ramirez (IL-3)56:09 – 56:10

That's right.

Samir Jain (Witness)56:11 – 56:12

voter registration databases and the like.

Rep. Ramirez (IL-3)56:12 – 56:22

Right. Well thank you, Mr. Jane. So Miss Darby, Mr. Ahern, and Mr. Sponholz, what are your states doing to ensure your elections are secure this cycle? And I'll start with Miss Darby.

Kristin Darby (Witness)56:25 – 56:30

So the election systems are outside of my scope of responsibility, so I can't speak to that um directly.

Rep. Ramirez (IL-3)56:32 – 56:33

Mister Ehren.

Colin Ahern (Witness)56:36 – 57:27

The State Board of Elections administers elections. Uh, we ha- we're a home rule state, so county and New York City administer elections. Uh, I'll say a couple of things. Number one, uh with the federal bureau of investigation the department of homeland security as well as the new york state police uh and the new york state division of homeland security and emergency services we run from primary day through election certification a secure election center in person in multiple locations around the state we have a deep and long-standing relationship with the center for internet security which houses both the multi-state information sharing and analysis center as well as the Elections Information Sharing and Analysis Center. Uh, and we're deeply committed to ensuring that the fully auditable paper ballots, which exist in New York State, uh, that people are confident in the election, they're confident in the results, and they're confident

Rep. Ramirez (IL-3)57:27 – 57:32

Thank you. My my time is up. If we do that next round, we will go to you. I appreciate it. Thank you. I yield back.

Rep. Ogles (TN-5)57:33 – 57:37

Gentlewoman yields back. I now recognize the gentleman from Florida, Mister Jimenez.

Rep. Gimenez (FL-28)57:39 – 58:11

Thank you very much, Mr. uh, Mr. Chairman. Um. I guess I'm going a little different different direction and and I don't know who can answer this, but would you say that our adversaries actually have a man power advantage when it comes to to uh our cyber attacks. That they they they far outnumber us, their offensive capability or number of people engaged in this, outnumber the number of people we have trying to defend against it. Anybody wanna answer that one?

Colin Ahern (Witness)58:12 – 58:51

Yes, sir, I I think uh one thing that I think is is to your point, sir, the Federal Bureau of Investigation last year indicted approximately fifteen members of an organization called Aisun uh which is a Chinese private company that was, as alleged in the indictment, used by the Chinese Ministry of State Security to to conduct surveillance on dissidents overseas to obtain, you know, economically and militarily important information in the United States. So, to your point, sir, they're using their own private sector to amplify the effects of their transnational repression, their economic espionage, and their theft of intellectual property.

Rep. Gimenez (FL-28)58:51 – 58:56

And did you say that they have far more people involved in that than we have defending against it?

Colin Ahern (Witness)58:57 – 59:13

I think from my perspective, sir, what I could say is that while we work every day, twenty four seven three sixty five, the rapid amplification and nature of the threat, clear that our adversaries are extremely well resourced.

Rep. Gimenez (FL-28)59:14 – 1:00:00

OK. Well, would you say that um, mister uh, Sponsor, would you say that I don't think we'll ever get to the point where we're gonna have the same, you know, you know, person to person, right, going at each other? That you say there's the advent of artificial intelligence for offensive purposes, but also can see that artificial intelligence can be used for defensive purposes and amplify our our our way to defend ourselves. And I think actually that's the only way we can go, okay, using artificial intelligence in order to combat their artificial intelligence. And I can see a day where we're attacking each other and defending each other a million times a second. Um, where are we on artificial intelligence on the defensive side?

Warren Sponholtz (Witness)1:00:02 – 1:00:38

Thank you, sir. This is something that the entire cybersecurity industry, whether it's uh corporate side or government side, a lot of attention to because um there's a really a a large pending threat around that uh vulnerability assessment and exploit uh generation that will just happen so much faster than what we're used to. So I know uh and speaking with our uh industry friends, uh they are working on solutions to be able to incorporate within the solutions we use today, uh so be able to bake in some addit uh additional protections. Um we are looking at it as I mentioned earlier about making it so that we can operate

Rep. Gimenez (FL-28)1:00:56 – 1:00:59

Yeah, cuz we could we could hire as many people as we want,

Warren Sponholtz (Witness)1:00:56 – 1:00:56

Yeah.

Rep. Gimenez (FL-28)1:00:59 – 1:02:08

okay? But in the end it's gonna be it has to be automated, cuz I don't see I don't see any way around it. Um, and so maybe the the the role of the federal government is actually to fund the and the defensive research that we need to automate our our our defenses against against their offensive capabilities and frankly also develop our own offensive capabilities well i'm sure we have um and and that would seem to be to be the only way that we can combat this and let machines fight you know fight each other at the end um in terms of election election security um i also believe that there is no systems that are absolutely safe and that the only way that we can get to uh and have election security that people are are confident in, so we have some kind of paper ballot, something that you can touch. Uh, and and you can't hack. Uh, so there's this we, you know, you bubble it in or whatever, and that at the end you can uh audit it, and you just have something some strange result, and you always go back to that precinct and say, is that is that the count that you got machine-wise? Does it match up with what you got ballot-wise? Uh, state of Florida, do we have ballot uh paper ballots?

Warren Sponholtz (Witness)1:02:10 – 1:02:23

I I I can't confirm or deny that, uh, Congressman. Uh, I know the state focuses a bunch of attention through Department of State on non-repud repudiation, excuse me, uh, in terms of elections, but I just don't have that information, but I can find out and can get it to you, sir.

Rep. Gimenez (FL-28)1:02:23 – 1:02:25

In the state of New York, you you have paper ballots?

Colin Ahern (Witness)1:02:26 – 1:02:26

Yes, sir.

Rep. Gimenez (FL-28)1:02:26 – 1:02:43

That's good, excellent. So we need to make sure that all fifty states have paper ballots, so that way it's the only way that we can guarantee, absolutely guarantee that we have election integrity, cuz if there is is a question, you go back to the good old fashioned paper ballot and count them by hand. Thank you and I yield back.

Rep. Ogles (TN-5)1:02:44 – 1:02:50

The gentleman yields back. I now recognize the gentlewoman from New Jersey, Mrs. MacGyver. Five minutes.

Rep. McIver (NJ-10)1:02:50 – 1:04:40

Thank you. Thank you to our witnesses for being here today. Uh, local governments hold some of the important information about our constituents, such as health care, tax, and criminal history records. but have some but have some of the fewest resources to ensure that this information is secure. Their budgets and personnel are stretched thin. Few local governments' entities have enough resources to track such as an ever-changing threat landscape. This reality can be devastating. Back home in my district and New Jersey's tenth congressional district, students at Cranford Public Schools had some of their personal information leaked in a nationwide cyber attack. This was alarming and challenging, but we know it could have been worse. We must act to ensure this does not become a routine part of life. However, this administration has decided to take a step backwards by putting a hiring freeze at CISA at the start of last year and pushing out over one thousand employees. Trump gutted a key tool in our fight for local cyber security. Although the administration appears to have realized the negative impacts of these cuts and started hiring, at CISA again, we must continue to demand adequate resources to ensure we are protecting every American's data at every level of government. Under the Trump administration, CISA has lost once again a thousand staff, or nearly a third of its workforce. These cuts have impacted all its divisions, including the regional offices that provide support to state and local governments. To all the witnesses, I would love for you all if you could elaborate on how important CISA is for cyber security right and cyber security experts on the ground throughout the country to provide support to state and local governments and also how has CISA regional staff helped state and local governments strengthen their security and respond to incidents

Colin Ahern (Witness)1:04:43 – 1:05:39

uh thank you ma'am maybe just a couple of points uh number one we have a close relationship with our CISA region two staff we've had the opportunity to meet multiple occasions across administrations with senior CISA leadership We have a deep partnership with the federal government. As I said in my opening statement, we want and need more of that partnership. Uh, and we had in twenty twenty two a very significant cyber attack against Suffolk County uh a county on Long Island uh and the CISA Region two staff, along with the local office of the FBI, along with the Secret Service, along with the State Police, along with the Suffolk County Police Department, created a tiger team to help respond to that event, along with the County Executive and his team. Uh, so we have real world ex- experience. of working directly in very significant cyber attacks directly with local communities. And that kind of team effort I think has has given us uh a very deep appreciation for the importance of the team sport that is cyber security.

Rep. McIver (NJ-10)1:05:39 – 1:05:42

Thank you. Anyone else care to elaborate? Miss Darby?

Kristin Darby (Witness)1:05:44 – 1:06:57

So with CISA we have um seen them as an important partner in providing guidance, services, coordination and information sharing. we believe the continued collaboration between federal, state, and local is critical because oftentimes as has been mentioned, uh the threats and attacks are coming from outside state borders. That being said, in Tennessee we have certainly seen significant excess with the whole of state approach the um combination that we have with local governments, uh local school systems, and many of our municipalities being able to work the state has built a strong awareness of not only the local needs but what those communities have from a maturity perspective in ways that we can cross that bridge and then use CISA as an organization uh to help us correlate and understand when threats or attacks are occurring is this um broader than the state of Tennessee is it localized and um they bring that intelligence that helps us the dots that are very important at critical times. Got it. Anyone else care to elaborate? We're less than a minute.

Warren Sponholtz (Witness)1:07:00 – 1:07:13

I'll just echo uh Chief Darby, that's exactly right. Just like uh the Florida CSOC serves as a a clearinghouse for threat information, CISA does something similar, there's nobody really else uh positioned to do that, so it's an important role and something we depend on. Thank you.

Kristin Darby (Witness)1:07:13 – 1:07:13

Got it.

Samir Jain (Witness)1:07:15 – 1:07:33

And I would just add, along with CISA and CISA's support coordination with the IMS ISAC, and that the ability to share information, to also provide monitoring tools and sensors and those kinds of tools to, particularly to local jurisdictions that otherwise wouldn't have the resources to um deploy those.

Rep. McIver (NJ-10)1:07:33 – 1:07:36

Thank you, thank you so much for each of your expertise, with that I yield back.

Rep. Ogles (TN-5)1:07:37 – 1:07:45

Gentlewoman yields back, I now recognize the gentleman from Texas. Thank you, Mr. Chairman. Good afternoon, everyone.

Rep. Luttrell (TX-8)1:07:48 – 1:10:26

Information flow is critical when you're talking about cyber security, cyber threat, cyber risk. You have the federal government, which moves at a snail's pace and anything that we can either move through committee or appropriate most likely land a few years later. Some of the challenges that I see, we only have three states, sorry, sorry, I don't know where you're from, I apologize. Unless you're somewhere over there not, I'm just gonna go with three, okay. Um, we have three states that have these issues and all of your opening statements, those issues were different. Similar, but they vary left or right. And we have to wade through the the weeds at any given level to say, okay, which one's right, which one's the most important, and which ones are we going to address? Now, attacks happen at the federal level from nation to state actors from local mom and pop shops down the street, and they happen to you too. Problem is, when they happen to you, oftentimes that's not communicated to us and The reciprocal of that is when it happens here, it's not communicated to you. Now we have CISA. Mister Haren, you s- you mentioned the Department of Energy. I don't know if Mister Harvey or Mister Spalhaus, do you, does the state touch the Department of Energy in any way? I I didn't hear you say that and I don't know. It's remarkable how valuable of an asset the Department of Energy is when it comes to the protection of the metaverse above us. But some states do not. Uh, this, my question, concern, is how do we corral the states, all of them, subject matter experts like yourself to address us, to give us, so we, the grant profile, I understand, CISA, very important, and I don't know if I can speak for the entire committee, but we're behind that, or at least I am. How about that? At least I am. Cuz I see the ones and the zeros, and I see the problem set that is scaling itself in a way that we can't control. And we would, I would personally love to give you everything that you need But I have three sitting in front of me that ask different things, and I if I had to have the rest of the states to come in and ask, just think of that and how challenging that is for us. Cuz if you can just convince the five of us that are in here today right now, we have to convince everyone else to get on board with that too. But it's very challenging if there's so much. Do this Do your counterparts, short of the three sitting here, collectively come together to give that to us. Or can you or will you? Ms. Darby, you can start it off, ladies first. I don't know why there's not somebody from Texas sitting on that role, but at the end of Tennessee, we we can work with that.

Kristin Darby (Witness)1:10:27 – 1:11:39

Well, thank you for that. So, I think there is um, so I'll speak first for the state CISOs. I know that there is a strong network where they have um, channels where they are connected on a daily basis. um, around emerging threats, they don't wait for, um, an administrative agency or to be told about things. There is, um, certainly that informal information sharing going on in a way that, um, we're all Americans and we're gonna make sure we're all protected, regardless of state borders. And we recognize that those threats, um, don't necessarily follow certain judi judicial, uh, jurisdictions, excuse me. Um, and so with that, I think the relationships and coordinations that happen informally are often more timely and more valuable. Um, it's not to say we don't need the other coordination because everyone has more formalized, uh, areas of, um, information gathering that's being provided, but those informal networks that have already formed through the opportunities for collaboration across um whether it's chief information officers or CISOs has been extremely valuable.

Rep. Luttrell (TX-8)1:11:39 – 1:11:48

How about this, if I was to ask the the four of you, how do we fix this problem right now, would the response you're gonna give me would be money?

Colin Ahern (Witness)1:11:51 – 1:11:52

I think so.

Rep. Luttrell (TX-8)1:11:51 – 1:11:58

Because you ask for it every I'm not wire brushing you please, but that's that's what we ask for every year and every year this problem gets worse.

Colin Ahern (Witness)1:11:59 – 1:12:35

I think, sir, there's two challenges that the committee has recognized that I think we see at the state level as well. One is the shrinking of CISA's capability making attenuating the operational coordination that we undertake through both formal mechanisms like the state fusion centers ours is called the New York State Intelligence Center uh based in East Greenbush New York there are fifty analogies around this country they have representatives from the FBI the Secret Service the alphabet soup uh and so we you know obviously ensuring that CISA is you know authorized and resourced to continue to

Rep. Luttrell (TX-8)1:12:36 – 1:12:54

So I have I have seven seconds and I apologize, Mr. Chairman, but if every state went directly to CISA and CISA was the one sitting in front of us saying this is exactly what every single state needs needs that might be a profound leap in the right direction. Does that even remotely sound like a good idea? I guess not.

Warren Sponholtz (Witness)1:12:56 – 1:12:57

Thank you, Mr. Chairman.

Rep. Luttrell (TX-8)1:12:57 – 1:12:58

Is that okay, Mr. Chairman? All right, thank you.

Warren Sponholtz (Witness)1:12:59 – 1:13:23

You um question about how do we get consensus, how do we really understand the problem, um fifty states. I would leverage some of the great communities we have like through NASIO, the National Association of State CIOs. There's great communities of practice within NASIO, including uh the CISO community. So to be able to get somebody working like from CISO with NASIO to help form s- c- some consensus on direction I think may be a path forward.

Rep. Luttrell (TX-8)1:13:23 – 1:13:47

Do you see how wide this net is being cast just in the conversation that we're having right now? I mean, a- again, And I don't know the best way to answer it. I've, you're the subject matter experts, but you just threw another acronym in an institution at me that I have never even heard of. And we have to wade through that in order to give either appropriate it or regulate it, correct? Thank you, I apologize. Thank you, Mr. Chairman.

Rep. Ogles (TN-5)1:13:48 – 1:13:54

The gentleman from Texas, Mister Lach- Littrell yields back. I'll I'll go to the gentleman from Virginia, Mister Walkinshaw.

Rep. Walkinshaw (VA-11)1:13:55 – 1:16:08

Thank you, Chairman Ogles and Ranking Member Ramirez, for convening today's hearing and for our witnesses for Joining us, uh, as we've heard at the very moment that state and local governments face more frequent and more sophisticated cyber threats, the federal government is pulling back and leaving them more and more to fend for themselves. CISA has lost a third of its workforce. I represent many of those third who have lost their jobs. Key programs have been eliminated or defunded. As we've heard from our witnesses, funding for the uh multi-state and elections ISACs have been eliminated, the state and local cyber security grant program has yet to be reauthorized, although there's strong support here to do that. But if you look at what has happened over the course of this administration, we've been lowering our defenses as a nation while our adversaries are getting more aggressive. Cyber attacks against state and local governments, up fifty percent. Iranian hackers targeting small water utilities in March of this year, caused global disruption at a major medical device manufacturer. Recently, as we all know, the education platform Canvas, attacked by a hacking group, gained access to millions of users' data, including students, teachers and staff. The attacks are growing in quantity and sophistication, and the consequences are stacking up. And to me, I think it makes one thing unmistakably clear. state and local governments and critical infrastructure operators need strong, steady federal support and partnership. And instead, we've seen the Trump administration walking away, abandoning these communities who are on the front lines of the threats. And I just wanna ask about some of that. Uh, when CISA cuts support for the MSI SAC, They said there would be a quote " new model". Um, mister Ahearn, are you can you talk us through what that new model is that CISA developed when they eliminated support for the MSI-seq?

Colin Ahern (Witness)1:16:10 – 1:16:12

I have not been made aware of that. New model, sir.

Rep. Walkinshaw (VA-11)1:16:12 – 1:17:01

Yeah, there is in the new model. The new model is governments that wanna participate can pay to participate. they offered no new services or new structure, uh, became a payment-based model. And, um, mister Jane, just under that new model, there's a risk that some jurisdictions maybe lose access, maybe they can't afford to, they have a tough budget year I've been in, local government, um, happen to be in one that would have the resources in most years to pay whatever the fee might be but those jurisdictions that might not have the resources to pay the fee to participate, you say they're more likely to be in urban areas or rural areas?

Samir Jain (Witness)1:17:03 – 1:17:17

You know, I I think it may vary. I think rural areas in particular, but it, I mean, what's particularly uh unfortunate about that is it's the jurisdictions that most need the help that are least likely to be able to afford.

Rep. Walkinshaw (VA-11)1:17:16 – 1:17:18

Small smaller jurisdictions.

Samir Jain (Witness)1:17:17 – 1:17:37

Right, the smaller jurisdiction, because if they don't have the resources and the money to join the ISAC, they probably also don't have the resources and the money to uh, you know, to buy equipment, to buy network monitoring tools, to sta- to have cyber security staff. So in some ways it's the - the ones who need it the most are the least likely to be able to get it, as a result of that model.

Rep. Walkinshaw (VA-11)1:17:38 – 1:17:59

Mister Ahern, in March of twenty twenty five uh the administration said that the Critical Infrastructure Partnership Advisory Council no longer met department priorities. Can you just talk us through in one minute what that was and what capability or capacity is lost with the elimination of that council?

Colin Ahern (Witness)1:17:59 – 1:18:32

Uh, yes, sir. In short, the Critical Infrastructure Partnership Advisory Council was a formal collaborative environment between state local government and the private sector. Uh, and we believe as part of this effort we should reestablish that body. We should bring in the cloud and other service providers on which state and local governments so dearly depend uh because those environments and that partnership framework is critical for ensuring that we have a continuous and accurate representation of the risk that these providers place to our government.

Rep. Walkinshaw (VA-11)1:18:32 – 1:19:10

Thank you, and I just you know I I really appreciated Mister Littrell's line of questioning, and his concern that sometimes everything sounds like it's gonna cost money, cost money, cost money. I would submit to my colleagues that one of the most cost-effective things we can do at the federal government level is play that convening role. There is no other entity that can as effectively bring together governments, the private sector, experts to share information and develop solutions together. I think that's a really, really good bang for our buck, and we're losing something with the elimination of that. Thank you.

Rep. Ogles (TN-5)1:19:13 – 1:19:18

The gentleman yields back, I recognize the gentleman uh from New York, Mister Lolota from Finance.

Rep. LaLota (NY-1)1:19:17 – 1:19:22

Thank you, sir, I agree with the gentleman from Virginia, we should do more uh about that. Um, Mister Erhen, how you doing?

Colin Ahern (Witness)1:19:23 – 1:19:24

Good to see you again, sir.

Rep. LaLota (NY-1)1:19:24 – 1:19:25

You're from New York?

Colin Ahern (Witness)1:19:25 – 1:19:26

Yes, sir.

Rep. LaLota (NY-1)1:19:26 – 1:19:31

And in twenty twenty two you were appointed New York's first Cybersecurity Officer?

Colin Ahern (Witness)1:19:31 – 1:19:32

Yes, sir.

Rep. LaLota (NY-1)1:19:32 – 1:19:36

And uh you were recently promoted to the Director of Security Intelligence in the Governor's office?

Colin Ahern (Witness)1:19:37 – 1:19:37

Yes, sir.

Rep. LaLota (NY-1)1:19:38 – 1:19:41

Um, so you're in charge of cyber security in the great state of New York.

Colin Ahern (Witness)1:19:41 – 1:19:42

That's correct.

Rep. LaLota (NY-1)1:19:43 – 1:19:46

Um, Mister Hearn, is cyber security important to Governor Hochul?

Colin Ahern (Witness)1:19:47 – 1:20:01

Yes, sir, I think Governor Hochul has proven both with our deep partnership with the legislature and the long-standing relationships we've established across the federal government uh that we take cyber security and cyber resilience very seriously.

Rep. LaLota (NY-1)1:20:01 – 1:20:05

Demonstrating that importance, she gave you a budget of about ninety million dollars?

Colin Ahern (Witness)1:20:05 – 1:20:06

Yes, sir.

Rep. LaLota (NY-1)1:20:06 – 1:20:22

Good. Um, earlier you mentioned a ransomware attack in my county, Suffolk County, in twenty twenty two. I wanna to say thanks for mentioning that. Um, do you know about, and if you don't know specifically, no harm, but if, do you know about how many ransomware incidents were reported in New York State in twenty twenty five?

Colin Ahern (Witness)1:20:24 – 1:20:33

Um, the numbers that I have is that the total complaint volume, according at least to the FBI's Internet Crime Complaint Center was approximately forty five thousand two hundred and fifty five.

Rep. LaLota (NY-1)1:20:33 – 1:21:22

You're very well prepared, sir. Thank you. Um, the the one that happened in the town of Southhold, the town in the North Fork of Long Island, in my district, Um, I don't know if you remember this, November of twenty twenty five, it was the week of Thanksgiving. They had an attack. Uh, the the attackers wanted about six hundred thousand dollars in cryptocurrency. They froze the town's email payroll, tax collection, building permits, decades of records. It took us weeks if not months to get everything back online. Um, we rightfully didn't pay the ransom. Uh, it took us about a half a million dollars to rebuild the system. Um. And it was a tough event for us and we wanted more help and uh we could have a conversation off-line about more the state and feds could have done for us there. Um But back to some other issues. Governor Hochul, she's your boss?

Colin Ahern (Witness)1:21:22 – 1:21:23

That's correct, sir.

Rep. LaLota (NY-1)1:21:23 – 1:21:27

You testified a few moments ago that cyber security is important to your boss.

Colin Ahern (Witness)1:21:27 – 1:21:28

That's correct, sir.

Rep. LaLota (NY-1)1:21:28 – 1:21:38

So important that you dedicated about ninety million dollars to the state's cyber security efforts including the things that have happened in in my county, the Suffolk County, in my town of for town of Southhold.

Colin Ahern (Witness)1:21:39 – 1:21:40

That's correct, sir.

Rep. LaLota (NY-1)1:21:41 – 1:21:50

So is protecting New Yorkers from cyber security threats more or less important to Governor Hochul um than the migrants who are in our country in our state illegally?

Colin Ahern (Witness)1:21:51 – 1:22:02

Well, sir, I think that the issue of public safety is deeply important, and while we're here to talk today about the importance of cyber security, uh, we don't believe that these are mutually exclusive concerns.

Rep. LaLota (NY-1)1:22:03 – 1:22:07

Okay. So the question is, is cyber security more or less

Colin Ahern (Witness)1:22:14 – 1:22:19

Sir, I think what is important is emphasizing the deep partnership we have with the private sector.

Rep. LaLota (NY-1)1:22:18 – 1:22:48

It's okay. I'll take it as a as a no answer. That's fine. Uh, Chairman, I want to submit into the record with unanimous consent uh from the New York State Comtrollers' website a report that Governor Hochul is spending four point three billion dollars on migrants' hotels, health care, uh and lawyers. Um, so she's spending four point three billion on the migrants, and she's spending ninety million on social security. We enumerated at least two incidents in my district that are important to my law abiding citizen constituents who pay a lot of taxes. You pay taxes, sir?

Colin Ahern (Witness)1:22:49 – 1:22:50

I do, sir.

Rep. LaLota (NY-1)1:22:50 – 1:22:51

Pay state taxes?

Colin Ahern (Witness)1:22:51 – 1:22:51

Yes, sir.

Rep. LaLota (NY-1)1:22:51 – 1:22:54

You know that we have the worst state tax climate in the entire nation?

Colin Ahern (Witness)1:22:56 – 1:22:58

Sir, I think that um

Rep. LaLota (NY-1)1:22:58 – 1:23:00

Just yes or no. Do you know that New York is dead last?

Colin Ahern (Witness)1:23:00 – 1:23:01

I did not know that, sir.

Rep. LaLota (NY-1)1:23:01 – 1:23:23

Okay. Unfortunately, it happens to be true. And yet, despite this issue, and we're here talking about important issues, the gentleman from Virginia makes a good point that we should all be doing more and you're here to ask for more money. The challenge that we have here is that your governor is spending forty eight times more on the migrants than we're spending on cyber security to protect law abiding citizens. Is that an issue for you?

Colin Ahern (Witness)1:23:25 – 1:23:37

Sir, I think that the issue of cyber security is deeply important. I think the issue of public safety is absolutely essential. but we don't believe that these are either mutually exclusive concerns, or should be set in opposition to each other.

Rep. LaLota (NY-1)1:23:38 – 1:23:56

Sure, but our budgets are reflective of our priorities, plenty of politicians that have have said that our budgets are our priorities. But when you're spending forty-eight times more on the migrants than you're spending on protecting law-abiding New Yorkers, that's an issue. Have you read recently about the governor giving uh Mayor Mondami four billion dollars to bail out his state budget?

Colin Ahern (Witness)1:23:58 – 1:23:59

Yes, sir.

Rep. LaLota (NY-1)1:23:59 – 1:24:07

Okay. And you know the the mayor wants to have free buses and government-run grocery stores and all this other nice socialist stuff in New York City. Are you aware of that?

Colin Ahern (Witness)1:24:08 – 1:24:13

I am aware of the comments about the mayor's priorities, yes sir.

Rep. LaLota (NY-1)1:24:13 – 1:24:33

Okay. So forty times more towards New York City's government-run grocery stores and the free buses and all the other socialist wish lists. Forty times more money to that than to cyber security. So I'll ask you, what's more important to Governor Hochul Mondami socialist agenda or protecting New Yorkers from the next cyber security attack?

Colin Ahern (Witness)1:24:34 – 1:24:39

I think number one, sir, that the issue of cyber security and the resilience of our infrastructure.

Rep. LaLota (NY-1)1:24:40 – 1:24:50

Forty, sir, forty times more money to one thing than the other. Is socialism more important to Governor Hochul than protecting New Yorkers from the next cyber attack?

Colin Ahern (Witness)1:24:51 – 1:24:53

The issue of public safety, sir.

Rep. LaLota (NY-1)1:24:51 – 1:24:55

Forty times more money. Forty times amount of money here than over here. Which is more important?

Colin Ahern (Witness)1:24:56 – 1:25:03

The issue of public safety is deeply important to our communities. And the cyber security of our of our communities is is is essential.

Rep. Ogles (TN-5)1:24:59 – 1:25:46

Chairman, I yield back. Gentleman yields back. So, we'll have time for uh additional questions and so I'll pick up kind of where we left off and and just kind of to summarize duly noted uh really from everyone but specifically Miss Darby and Mister Jane about the the lower match in particular for the rural, uh poorer communities uh grant flexibility, a response fund, and like a zero day type apparatus, but picking up with you, Mr. Hearn, um when you th- look at rural communities, small communities, how do we specifically address n- them not being left behind?

Colin Ahern (Witness)1:25:47 – 1:27:10

I think number one, sir, it's the shared services that each one of our panelists have commented on. Uh, as you know, my uh the my colleagues from both uh Tennessee and Ver- and Florida have mentioned the ability of using whole of state cyber security shared services to make sure that we can substantially mitigate both the cost and the complexity of deploying these tools is essential one of the things I think that we've all found uh is through the grant program's current structure it is harder to do that and we should make that easier I think the comments from uh the judge a woman from Tennessee are very important in considering how that might be done we share those concerns Uh and number two, we found that by engaging in statewide contracting, we're able to bring down the cost of those services. And one example is we saved county and local governments nineteen million dollars on one part of our shared services. And just recently by going with a whole of state grant program, much like my colleagues, we're able to bring down the cost of multifactor tokens by approximately twenty-one percent uh and that wouldn't be possible for uh a county or a local government in some cases to cover that match requirement so because we could lower the cost we ended up being able to cover the cost share requirement as a state within the state budget uh and so that could you know enable us to cover even more entities that would not be able to participate before

Rep. Ogles (TN-5)1:27:11 – 1:28:01

well and on that note um you know as my colleague from new york uh obviously very passionate about the budget um is you know making sure that states are actually paying their first share So you have a large state like New York that is, you know, the state set their priorities, right? Um, obviously cyber security is an important issue. Um, and so as we go, that's really the challenge we face is, you know, I'm sensitive to the small rural community aspect because that's where I was a county executive, and we experienced a cyber attack, and we have a very forward-thinking leader, quite frankly, on cyber security in Tennessee and Vistarbi. But then, we've gotta figure out a way that we're helping the rural communities without propping up some of the big cities. And so that's the challenge we face today as we go forward. And um, so it's you, sir, Mr. Spunnels.

Warren Sponholtz (Witness)1:28:03 – 1:28:50

Thank you, Mr. Chair. Um, completely agree, our strategy in Florida has been to focus on the rural communities, uh, and the physically constrained communities, whether that be the state program or the federal program. Uh, definitely prioritize them as well as our critical infrastructure assets throughout the state. recognizing that um they have uh difficulties being able to um buy some of those kind of uh solutions that that are that are uh critical to protect their um information systems and i'll just uh add on uh what mister ehren was talking about in that not just uh driving down the cost but a lot of times some of these solutions the um the rural and smaller communities are too small to even be able to be to to purchase some of these solutions, right?

Samir Jain (Witness)1:28:50 – 1:28:50

Mm-hmm.

Warren Sponholtz (Witness)1:28:50 – 1:29:18

So, some of these solutions expect larger implementations and larger sales, and unless it's done through some larger purchasing mechanism, uh, they won't even, uh, uh, work with some of these smaller communities. So, uh, multiple, uh, benefits, we've seen tremendous savings through, uh, bulk purchasing, uh, four to one savings last year, which was, uh, was just something that was really, um, amazing for the state, uh, to be able to cover more, uh, local entities through through our through our grant programs. Interesting.

Samir Jain (Witness)1:29:20 – 1:29:57

Yeah, I think w- I would add in addition to money, a a lot of these jurisdictions lack staffing, lack the lack the expertise in staffing. Now part of that is not having the money to hire people, but it also means this is where CISA can really make a difference in terms of having being able to provide expertise, um to the local and jur- uh rural jurisdictions to conduct do things like conduct penetration testing and identify particular vulnerabilities that their s- that their systems may face. And so I I think this is a place where, you know, CISA, where I having it, the ability to join the ISAC without having to pay for it, and to gain the benefit of that kind of intelligence and threat sharing, um, is also critical.

Rep. Ogles (TN-5)1:29:57 – 1:30:04

Alright. Uh, what we'll do is, um, I'll yield back, I'd like to recognize, uh, the Ranking Memor- Miss Ramirez for five minutes.

Rep. Ramirez (IL-3)1:30:05 – 1:31:28

Thank you, Chairman. I I wanna just respond for a moment, um, regarding budget's been moral documents. I couldn't agree more. budgets are moral documents and spending a billion dollars on a ballroom which is what the president wants or one point seven billion dollars to incentivize insurrectionists while we still are waiting for the reauthorization of this critical grant program says a lot about where priorities are right now with this administration i just wanna make sure for the record that we state that while it's really easy to start um blaming immigrants for everything i think but at the end of the day we have to ask ourselves, those of us that are actually prioritizing and have the influence over budgets, prioritizing ballrooms and incentivizing insurrectionists, while cyber security is not being funded at the levels necessary, says a lot about where our leadership is. But then I wanna come back to the conversation here. Rapid advances in frontier AI models are reshaping the cyber security landscape. We've heard from your own um testimony today. uh what is happening and the threats and the impact that your own s- respective states are having. For many state and local governments with limited resources, this creates many new challenges to defending your networks. Mister Jane, what are potential risk frontier AI models posed to state and local governments and their constituents?

Samir Jain (Witness)1:31:30 – 1:32:07

I think there are several different types of threats. One is that, you know, we've seen with mythos, the anthropic model, and open AI's most recent model, that they're able to discover um vulnerabilities sometimes vulnerabilities that have been embedded in systems for years without discovery and if the those kinds of um capabilities get in the hands of other nation states or any criminal actors then they can identify vulnerabilities in state and local systems um perhaps more quickly than um those jurisdictions are able to patch them or to uh address them and so there are more vulnerabilities that could be exploited and can be exploited much more quickly

Rep. Ramirez (IL-3)1:32:08 – 1:32:08

Mm-hmm.

Samir Jain (Witness)1:32:08 – 1:32:36

than has happened in the past. Um, two, as state and local governments understandably and rightly use AI for more services, you know, provide chat bots through which constituents can interact with governments, um, and um, you know, use AI to help with their own co- coding their own systems, that use of AI itself introduces new vulnerabilities because those AI systems have access to data about people and they themselves then become a potential conduit for potential um, attacks.

Rep. Ramirez (IL-3)1:32:36 – 1:32:37

Mm-hmm.

Samir Jain (Witness)1:32:37 – 1:33:01

And then the third point I'd make, which I mentioned earlier, is is that AI also allows for more efficient and more damaging exploitation of the data that does get taken in a breach. So it becomes much easier to draft, you know, very authentic phishing emails or to impersonate people, um, using AI, uh, to, generative AI to create those things. And so it makes the consequences and the harms of the breaches even worse,

Rep. Ramirez (IL-3)1:33:01 – 1:33:01

Mm-hmm.

Samir Jain (Witness)1:33:01 – 1:33:03

um, when the bad actors have AI.

Rep. Ramirez (IL-3)1:33:03 – 1:33:14

Yeah. So my last question um comes back to Mister Ahern. What is your state need from the federal government and from AI model developers to better secure your networks?

Colin Ahern (Witness)1:33:14 – 1:33:50

I think number one, we want the reauthorization of this grant program. As has been said before, we think it should be more straightforward to use them for shared services. Number two, we think that the cuts to CISA should be reversed. We think that some of the important convening mechanisms uh as as the representatives said are deeply important and there isn't another secret team that can do that convening the office of the national cyber director the cyber security infrastructure security agency and the federal government is the essential partner in ensuring that we remain united against these threats

Rep. Ramirez (IL-3)1:33:50 – 1:34:06

thank you so i heard you say the reauthorization of the grant program that the cuts to cca be be reversed and that we be the ones that are convening public and private partners to ensure that cyber security is top priority for us. Thank you. With that, uh, Chairman, I yield back.

Rep. Ogles (TN-5)1:34:08 – 1:34:13

The gentlewoman yields. I'd like to recognize the gentleman, uh, from Virginia, Mister Walkinshaw.

Rep. Walkinshaw (VA-11)1:34:13 – 1:34:27

Thank you, Mister Chairman. Um, I'm I'm sorry Mister Lolota left, but Mister Ahern, uh, during Governor Hochul's tenure, has the budget in New York for cyber security gone up or down?

Colin Ahern (Witness)1:34:28 – 1:34:28

Up.

Rep. Walkinshaw (VA-11)1:34:29 – 1:34:36

Okay. Um, do you know what CISA's budget was in FY twenty twenty five?

Colin Ahern (Witness)1:34:36 – 1:34:37

I do not, sir.

Rep. Walkinshaw (VA-11)1:34:37 – 1:36:33

Okay, it was three billion dollars. Do you know or any of our panelists know what President Trump requested in his budget for CISA in fiscal year twenty twenty seven? Two billion dollars. So we we are looking at a cut in one third, a one third cut in federal funding for cyber security. And as the ranking member noted, if President Trump gets his way, in all ways, we'd be spending a billion dollars for the ballroom, one point eight billion dollars for the January sixth slush fund, two point eight billion dollars just on those two items, eight hundred million dollars more than his total commitment to cyber security. I'm sure Mister Lolota knows those numbers as well. Um, I did wanna ask all of you, I think one of the challenges we have in this conversation is how do you measure success? And it's certainly a challenge we've had in federal agencies. And typically the numbers we hear, we've heard some of it today, uh the number of attacks has increased right, as fifty thousand attacks in New York or millions and millions of attacks. I don't know if that's a useful number other than to help us understand that the scope of the challenge is is significant. But I'm interested for each of you in your respective states, Miss Darby and and Mister Ahern, and Mister Sponholtz perhaps, how do you measure success, how do you determine whether your cyber security pro posture set aside the attacks that come in maybe out of your control, but how do you measure whether your posture is stronger today than it was yesterday? Maybe we'll start with Ms. Darby.

Kristin Darby (Witness)1:36:34 – 1:38:07

Thank you for the question. So in Tennessee we have specific outcomes around every measure. So it's number of endpoints uh protected. It is um cyber security training. And uh is that reducing uh whether it's phishing attacks uh or or end resulting attacks as a result of that. So we have specific outcomes where um we focus on each of those. One of the the other areas that I would I would just offer in reflection of what's been discussed here today is um we've all expressed our um desire for the grant program to be renewed and believe it has prof- provided significant value. but it was designed four to five years ago, and the climate has transitioned and changed. I do believe scarcity often ignites innovation, and using this as an opportunity that if the grant program is renewed, do we look at different ways to identify what those outcome measures are that you're asking about, but also look at um for for a central convening organization, i think it also provides an opportunity to bring together national experts in ways that can help all the states leapfrog the capabilities that ai has introduced we are all um trying to figure out how to pivot traditional operations to future and there's a real opportunity here to do things differently

Rep. Walkinshaw (VA-11)1:38:04 – 1:38:10

yeah thank you m- mister ahren metrics of success for you all

Colin Ahern (Witness)1:38:09 – 1:38:23

i think yeah i think number one is we know that bad things are gonna happen there's you know there's adversaries on the other side of the world on the other side of the keyboard but number one from us is the time from from detection to confirmed remediation

Kristin Darby (Witness)1:38:21 – 1:38:22

yeah

Colin Ahern (Witness)1:38:24 – 1:38:43

uh and just one statistic we shared in our testimony with the state's shared services program when you're within uh you know the state's program it is thirty seven minutes from detection to confirmed remediation on average whereas without that shared services enabled in part by this grand program it is two thousand eight hundred and eighty minutes

Kristin Darby (Witness)1:38:41 – 1:38:41

hmm

Colin Ahern (Witness)1:38:43 – 1:38:52

two full days. And that's the difference between using automation, cloud-delivered services, twenty-four by seven security operations center, uh to

Rep. Walkinshaw (VA-11)1:38:52 – 1:38:58

Obviously the attacker can do a lot more damage in that much longer time period. Yeah. Okay, Mister Sponelts.

Warren Sponholtz (Witness)1:38:59 – 1:39:47

Yes. Uh, thank you for the question. So, uh, just briefly, couple uh ways beyond what's been discussed already is um being able to measure uh the impact of a of an incident where we have protections, right? So Um, we expect that where we have better protections, better solutions, better training, uh, we're gonna have reduced, um, uh, uh, impact and, uh, effects to the to the organization. Little bit easier to meas well, excuse me, a little bit more difficult to measure, but something that's important to see how well our, uh, controls are working. Uh, and then secondly is time to provide contextualized information to locals and uh state agency partners. Uh, so if we find something, getting that information to them, as quickly as possible with good uh context on what the problem is, why it matters to them, and how they need to remediate.

Rep. Walkinshaw (VA-11)1:39:48 – 1:39:52

Thank you. Mister, if the chairman will allow, Mister Jane, if you have any any thoughts on that?

Samir Jain (Witness)1:39:54 – 1:40:22

Uh the only thing I uh other thing I'd add is another measure of success is really to what degree are constituents being harmed or not harmed in terms of are they suffering identity theft or some of the harms that can come from theft of personal information to what degree are s- are critical services off-line and not available to them over the cor- as a result of a cyber attack. So I think looking at it from the point of view of constituents and consumers, and what harms they are or aren't suffering, and minimizing those is really an important measure of success.

Warren Sponholtz (Witness)1:40:22 – 1:40:23

Okay. Thank you. You're back.

Rep. Ogles (TN-5)1:40:25 – 1:42:18

You know, John Quincy, I love the House uh representatives, cuz it's where you argue and debate. And um and so we can argue about the numbers. You know, the House appropriation for uh CIS's FY twenty-seven is two point five billion. There's an a hundred and eighty five point eight billion cut over this twenty-six fiscal year. Uh, there is a five point one million specification there for additional security advisors, and specifies uh fifty-three uh personnel in particular. So that being said, uh, to the idea of scarcity. So we're seeing cuts and we can agree or disagree whether that's a productive thing. But we also know the government can't do this alone. That we need to have integration with the private sector uh in some of these NGOs that dabble, if you will, or pioneer in AI. And so, as you look at coordination and collaboration, as you look at response time, Mister Hearn, um, i- if we sat down at a table and setting everything else aside, CISA, whatever other alphabet agency that might be there, and we were to create a construct of how do we make sure that that breach in New York or Florida or Virginia is instantly known in Tennessee or vice versa. Cuz res seconds, it's kind of like a nine one one call, you know, where a minute matters. And I would think arguably in this space, in this environment, because it is so rapid, and the data is so portable, the seconds matter. So how do we fix it? So I think it, you know, because of uh the amount of time we have left, I think this is an opportunity to, and obviously we'll be respectful one another's times and such, but to create more of a back and forth round table approach of like how do we fix this because we know it's a problem and we can't just throw money at it if we don't have all the partners at the table so we've we've picked on you mister harvey you've had to lead off every time so why don't we go this at this end of the table and we'll go that direction uh so mister jane

Samir Jain (Witness)1:42:20 – 1:43:22

sure so i mean i think this is where uh constructs like the isacs are really important in terms of being more of a hub and spoke kind of a model because you're right that you need the information sharing really flowing in both direction in three directions from states you have state's private sector and you have the federal government and you need information flowing bi-directionally from both in other words when one state suffers an attack communicating that to the hub so that other states become aware of it and can become alert to the possibility that they're gonna suffer the same kind of attack so that kind of bi-directional information sharing obviously the private sector has insights and information that the governments are not they're gonna see things um that the government's not and the federal government has unique visibility into things like nation state campaigns, what are their objectives, what are what what are they trying to accomplish. So I think you're certainly right that you need the private sector at the table as well, in that um but I do think then you need a hub or a place or a mechanism for that information both to get ingested and then um propagated back out.

Warren Sponholtz (Witness)1:43:24 – 1:44:31

Thank you, Mr. Chair, um I think I mean, I know we have the technology today, so we have great tools and solutions to be able to do rapid intelligence sharing. Um, I believe it's a matter of priority to some degree to be able to focus in on that mission and do it and do it well. Um, mentioned before about our communities of practice, uh, such as the ones that exist in the National Association of, uh, State CIOs, to be able to generate support for that kind of information sharing, I think that, uh, would be a, uh, a great path to be able to, uh, get a coalition of states uh across the nation to to participate in information sharing. And I just believe that information sharing um is one of the most critical things we can do to to stay ahead of uh some of the threats we face today. Uh and I'll just just close um with this question as far as some sort of federal guidance around working with our commercial partners to figure out what's the solution to some of these pending um AIRI threats that are that are around the corner for us is critically important and I don't know who else is doing that if it's not gonna be the federal government so it's important that they stay in that fight thank you.

Colin Ahern (Witness)1:44:32 – 1:45:56

yeah I think just a couple of other thoughts I think from the fine you know from the great panelists here number one I think you know authorities, appropriations and capabilities authorities we have the CISA twenty fifteen information sharing act uh which has received you know bipartisan support uh is also expiring uh relatively students would be reauthorized that's one of fundamental mechanisms that enables information sharing from the private sector to the federal government uh appropriations uh so as you mentioned uh appropriations are a part of this but the capabilities that we have at the state level at the federal government level and within the private sector uh i think we wanna be uh even more pointed about using the state fusion centers which are already situated at the intersection between the private sector the federal agencies and the state and local governments uh and those capabilities moving beyond just throwing emails over the wall but into operational collaboration that I think unfortunately we tend only to see uh you know when there are gray skies or black skies uh but we want to extend that operational coordination that capability development in across the operational spectrum uh and that'll only happen with um you know with all of these elements in place Uh, but, sir, I think that as we've seen in New York, it is possible to do that. Uh, and we are eager to partner with the federal government and the private sector in that effort.

Warren Sponholtz (Witness)1:45:57 – 1:45:58

Mr. Arby?

Kristin Darby (Witness)1:46:00 – 1:47:35

So Tennessee, I think, has remarkable um cyber security maturity and has done well in this particular positioning. But I do think the uh environment that we are in right now has created new dynamics that are significant in material. and would challenge that um you know when we think of kinetic situations the the federal government has um large tentacles in intelligence that start to lead and allow reactions in the cyber security area it feels like oftentimes we're getting intelligence after things have occurred versus proactively and so maybe it's a um what comes to mind is just a um a think tank of national experts that are positioning the states to be able to leapfrog their level of expertise around this changing dynamic. States often struggle with um attracting the best talent. I'm sure the federal government has a common issue. Part of this grant program redesign perhaps is a way to create an opportunity for an innovations uh group that attracts the nation's best leaders, that will allow us to understand how do we start to understand that these models are gonna be democratized with access, that it is no longer just nation state leaders we have to be concerned about, it is local, very intelligent maybe um individuals that are focused on doing harm, that now have access to these tools and they can scale in ways and speed that were not present in the past.

Rep. Ogles (TN-5)1:47:39 – 1:48:33

So, if I may um If a ransomware attack were to shut down a major health care system in Tennessee, tomorrow disabling electronic health record systems, medical devices, communication systems, et cetera, billing, et cetera, um, and respectively to each of your states, whether it's health care or water infrastructure, et cetera, you know, walk us through, and I think it's important, the reason why I pose this question is for those watching the community at large to understand on the record that what's at stake. So when you, when you talk about the salt typhoons, typhoon and gold typhoon attacks, the pre-positioning of software and critical infrastructure, but essentially with the flip of a switch that it could be turned on or off. Um, what happens in that moment, and then what are the repercussions, especially with, you know, Tennessee's Music City USA, but it's also considered by many as healthcare USA because of Nashville. Mr. Arby?

Kristin Darby (Witness)1:48:34 – 1:49:26

So in that particular situation, we would certainly work with the um appropriate individuals at the hospital to be able to understand the situation, offer resources immediately, which um would certainly include the state cyber security resources, but also the connection with our law enforcement agencies, um TBI being one of our most prominent uh partners that is uh very responsive to ensure that we are doing everything we can to make sure the threat is isolated and then mitigating any further damage. Um with that we would then um focus on investigation and recovery with them. Uh, the hospitals also are well prepared for those types of scenarios to be able to ensure patient safety and mitigation and we would support those efforts from a state perspective in any way that is necessary.

Rep. Ogles (TN-5)1:49:27 – 1:49:42

And and to the rest of the panelists, you know, do you have whether it's a hypothetical situ hypothetical situation, but moreover, do you have a real-world example of what happened in say New York, where you had some sort of critical infrastructure situation, there was a But what did what what did that mean for the community at large?

Colin Ahern (Witness)1:49:42 – 1:51:18

Yeah, I think it's a great question, sir. And I think, you know, we had one Brooklyn Health, which uh is a a a hospital system in Brooklyn which serves primarily underserved uh communities in the you know in in that area uh and it means going on diversion as you prob- as everyone is aware you know telehealth you know, radiology delivered over the internet, uh stroke, emergency rooms, you know, those are all things that run on computers. I would note that New York is uh to our knowledge the only state that has enforceable minimum standards for hospitals what we call article twenty eight facilities uh in November of twenty twenty three the Governor directed the Department of Health uh to not only enforce minimum standards which um you know we think are important like multi-factor authentication like hardening but also having paper plans for going on diversion so that we can minimize the impact to our communities when these unfortunate incidents do occur uh and so we have a reporting regime through the department of health through uh the uh new york state local uh health administrators association uh and with you know uh our federal partners to ensure that we understand their ramifications especially for our rural hospitals who might be one of the only emergency rooms uh within a thirty mile radius uh so we have developed plans with our office of fire fire prevention services and others to make sure that we can uh allocate the appropriate emergency resources when these incidents do occur because as you said sir these incidents are unfortunately uh picking up in pace.

Warren Sponholtz (Witness)1:51:21 – 1:53:00

Thank you, Mr. Chairman. So continuing with the um hospital scenario so uh we did have our fairly recent uh incident with the hospital and uh we worked closely with the agency for healthcare administration, florida agency that um uh helps administer and oversees hospital operations throughout the state and and care centers throughout the state uh they have a good handle on the uh communication channels uh that exist between the state, other hospitals uh so work closely with them to insure um like chief darby said isolation happens so that things all continue to spread across the healthcare system uh which is very important and uh mr. chair you mentioned about the impacts to uh the communities and the people who use these services So, um, when a a a ransomware attack happens, you're also breached at the same time. You can count on that. Um, and the the the terrible thing about that is that information is not just used, um, as as leverage for for some sort of payout, uh, but it's also used in subsequent attacks. So they use that information to be able to do, uh, fraud against, uh, people and affecting their lives. Uh, they use that to try to break into other people's accounts and they use that, uh, just to - to - to formulate enough information to build a future attack. So, not only does it have the immediate effect of breaking operations, it has the longer effect of impa- affecting people's lives and the further impact of setting up tomorrow's attack. So, uh, something that, um, is just another, uh, example and reason why, uh, the investment and the attention to cyber security protections, uh, is so, um, imperative. Mister Jane?

Samir Jain (Witness)1:53:02 – 1:53:43

Fortunately, I'm not in a position to having to respond to those kinds of attacks. But, you know, I I think picking up on the point that uh Miss Darby made earlier about innovation, I think um, you know, we've talked a little bit about the use of AI in defense in terms of preventing attacks, but I think AI also has a potential for helping with incident response itself, and um being able to process data, being able to um figure out how to respond more quickly, and you know we have the ai labs who have a lot of expertise in terms of how to use their systems and i think you know we're talking about you know glasswing and these collaborations that the ai labs are doing in terms of um cyber security i think turning a little bit of that to incident response would be useful as well.

Rep. Ogles (TN-5)1:53:47 – 1:55:20

so as we start to close out the hearing what i would love to get uh one from you in writing so you can have time to think about it would be just sort of a best practices uh that you might recommend. Uh as we've said we've passed um the Pillar Act here in the House, which authorizes it uh the the grant program through uh fiscal year thirty-three. We're waiting on action in the Senate. So as we go forward there may be the opportunity to make some revisions, and if no, we can have another piece of legislation that really m- perhaps as Miss Darby, Darby I do believe you said, gives that flexibility as you're trying to help say Murray County with the grant program sort of thing so I would love to get those. Um, so we can compile kind of what are the next steps, because I I I I fear this will be an ongoing uh conversation where every, every so often we're having to revisit this type of how do we respond to that next level of type. Because when you look at like Chad or Brock, a year and a half ago, that was a, that was a a a a search engine on steroids, right? Now you have the, these agents that are almost thinking, if you will, at least in from a computer uh standpoint, but they're very dynamic. And so what does eighteen months look for now? Or six months from now? So, we'll start with you, Mister Jane. Mister Arby, I'll give you the final word. Uh, but what are your closing thoughts? Anything that you wanna reiterate? I understand that we we need to address CISA, make some revisions there, but I like the idea of scarcity because we're trying to get the private and the and the non-profit sector involved in this conversation because government is not the the the one hundred percent solution. It's gotta be this coordinated effort, Mister Jane.

Samir Jain (Witness)1:55:22 – 1:56:10

Yeah, I mean, I certainly agree that it needs to be a coordinated effort among all stakeholders. And, you know, part of the private sector now that needs to be more involved, I think, is not just the cyber security companies but the AI companies themselves, because they're bringing to the table these new capabilities, um, both offensive but defensive as w- uh, I think potentially defensive as well. So I agree with that. You know, beyond that, I think, you know, resources aren't gonna be enough, but you do uh, I mean, the the resources are sort of a a base level that you need um in order to um be able to deal with cyber security because without those resources particularly when we're talking about the smaller jurisdictions or those without the staffing or the budgets if they don't have that minimally it really doesn't matter what you have in the way of capabilities because they're not gonna be able to utilize them

Rep. Ogles (TN-5)1:56:11 – 1:56:48

well i to that point you know uh i i won't say his last name but bill who was was my i t director you know he was also the guy plugging in your keyboard and changing out the monitors and resetting passwords and, you know, building the network for the county and helping the hospital, uh, but he was also the guy that would had to have to defend the the county and the hospital and the school system in coordination with the school's resources, from a cyber attack, right? And so like you had one and a half individuals, uh, having to fend a county and a community from perhaps a nation, state, actor, or today from an agent, you know, an AI agent. So Uh, I do know we have another member coming, but we'll go ahead and up to you, Mister Sponholz.

Warren Sponholtz (Witness)1:56:50 – 1:57:48

Thank you, Mister Chairman. So I'd say a couple things. One is to um continue on with leadership around um exploring solutions to um the the the coming threats around AI and vulnerability development um with with commercial um AI companies as mentioned uh as well as uh with the federal government, just taking the lead there. Um, secondly, I'd say in respect to the federal grant, um, as much flexibility as possible, um, would be, um, well used just because every state's different. Um, so different needs, different ways that that state's gonna be able to execute, uh, with that money. And those kind of things are really hard to, uh, dictate or to, uh, specify at a federal level. Uh, but if states are given the, uh, freedom and flexibility to be able to tailor how that money is used within their respective states, to as much as possible. I think you'll get a more efficient use of those funds and more protection for for every dollar with that flexibility.

Rep. Ogles (TN-5)1:57:51 – 2:00:22

When you look at the grant program um and the deployment of AI agents, um is there enough flexibility in there for the training for your staff or future staff? But because, you know, I've had the the the privilege or misfortune of being able to use jailbroken AI. And the prompts that I was able to put in and get a very detailed answer on are horrifying, to include uh how to construct a uh weapon of mass destruction a bomb from hardware supplies, how to what was the ideal vehicle to put it in, what would be the blast radius, um so as to not be injured myself, how to build a remote detonator, from off the shelf items. And so people need to understand that this is coming down the pike. And when you have countries like China, whereas we try to have guardrails here in the US, you have a threat actor, a nation state, that isn't as concerned with safety. So when you go back to the Cold War, we had this arms race with Russia, and it was about who had the most nuclear weapons. Well, there came the point of mutual destruction where we could all blow up the, yes ma- uh, world many times over. So then it became about delivery systems and who could do it the fastest, but what is it eight minutes, ten minutes, or twelve minutes? It's still just minutes. With AI, this horizon doesn't exist. And the speed at which the capabilities are are accelerating is almost unfathomable or unfathomable. And even then though it was between two nation states. Now, you're gonna have some knucklehead in a basement somewhere if they get the right technology, can do this. And so I wanna make sure as you move forward in any, that next piece of legislation as we're looking to defend states and communities from this type of threat that we're actually equipping you with the tools that are gonna be helpful. So as we go forward, I'll I would love, I'll give each of you my number, uh, to stay in touch, to make sure that as we apply some sort of grant, or pool or resource available to the states that it's actually in real time, like in the in in the labs of deployment, which would be the states, that it's effective. So I will pause there and recognize the gentleman, you ready? Or do you need a moment?

Rep. Fong (CA-20)2:00:23 – 2:00:24

Uh, thank you, Mister Chairman.

Rep. Ogles (TN-5)2:00:25 – 2:00:27

Mister Fong from California, five minutes.

Rep. Fong (CA-20)2:00:28 – 2:00:46

Uh, without objection I'm entering into the record a letter from the Operational Technology Cybersecurity Coalition. the alliance for digital innovation the cyber security coalition and the information technology industry council dated uh may twentieth twenty twenty six uh this letter urges continued support for the state and local cyber security grant program and highlights the need for

Rep. Ogles (TN-5)2:00:44 – 2:00:45

you're so

Rep. Fong (CA-20)2:00:46 – 2:01:29

continued cooperation by federal entities with the state and local governments um apologize for being a little late uh transportation mark up is still going but um uh earlier this year i hosted a round table along with uh along with chairman garbarino in my district where we discussed the importance of current and uh future cyber security challenges facing the central valley and across california i have a lot of rural communities military installations um and so um the soft targets around those installations such as water power um health care infrastructure remains a top priority within your state's critical infrastructure sectors how have you all worked uh to update uh the cyber security capabilities especially with what's going on with mythos and everything else and i apologize if it's repeating but i i would like to get your perspective

Colin Ahern (Witness)2:01:31 – 2:03:02

Yes sir, I'll start. I think number one, uh in twenty twenty two, Governor Hochul signed first in the nation legislation giving our public service commission the authority to regulate cyber hazards on par with other hazards that resulted in rule making uh which we believe has materially advanced the cyber security posture of electrical distribution utilities uh number two uh in twenty twenty three as I mentioned previously uh our department of health enacted first in the nation's cyber security standards, along with a significant grant program to update uh the technology posture of hospitals in the state, in particular rural hospitals uh which is uh I think we all understand are are particularly important targets for our communities. Uh and number three uh actually just last month our Department of Environmental Conservation our Department of Health and uh our Public Service Commission are moving forward with water and wastewater cyber security minimum standards as well as a grant program and technical assistance program uh which is built upon the cyber security performance goals shared by the environmental protection agency and the cyber security information uh security agency um and so we think that our approach by you know threat centric risk centric and cost conscious minimum standards paired with technical assistance and grant programs the likes of which are are deeply and importantly integrated with the state and local cybersecurity grant program uh are important for especially rural communities in uh those those areas.

Rep. Fong (CA-20)2:03:04 – 2:03:20

If I could follow up and and any of you guys can jump in, uh the rural community part you mentioned, how how do you how should rural communities um um with build out their their their capacity uh especially I I I would like you to kind of dive into that a little bit.

Colin Ahern (Witness)2:03:20 – 2:04:08

Yeah, and I think um as my co-panelists have all said we need to make our shared services easy to consume for a person who uh has a lot of other jobs. We also have uh Ed uh who is the deputy county executive of Real County. He's also a full-time exterminator, father of three, and the IT guy. So this has to work for Ed. Ed is a, Ed is a smart guy. It's not that Ed's not a smart guy and Ed doesn't care, that's not true. It's that he is very busy. So sending Ed a PDF isn't gonna help ed sending ed something he can double click that's you know more like a sandwich than a puppy uh i think has has been our approach and has been one that has led to fifty five counties thirty four cities villages and towns dozens of sheriff's offices across the state participating in our shared services program

Rep. Fong (CA-20)2:04:09 – 2:04:12

anyone else wanna jump into to this conversation

Kristin Darby (Witness)2:04:13 – 2:04:39

yeah i would just reiterate that um uh low touch high impact solutions of what we have seen be successful across tennessee uh the rural communities um uh are have a strong commitment to increasing their cyber protection, but they don't have the man power. And so, managed solutions and different types of automated solutions are going to be critical for those areas.

Warren Sponholtz (Witness)2:04:41 – 2:05:11

And just to triple stomp it, um we include uh managed services along with all the shared services that we provide. So um they'll have assistance from the uh from either a third party a managed service provider or from the solution provider itself to help install and configure and get these solutions set up right uh because um just as stated by mister ernie um ernie sorry um these people have lots of different roles very very busy um they really need help to be able to get this stuff going or it'll just sit on the shelf

Rep. Fong (CA-20)2:05:12 – 2:05:30

my time is running out but i i do wanna highlight the fact that we have we're we're also focused on workforce and i think that's an area that we need to create pathways into uh the cyber security space uh as to build a capacity uh not only in the urban centers but in the rural communities as well and I'd love to to to follow up with you and partner with you on that thank you Mister Chairman for the the time.

Rep. Ogles (TN-5)2:05:31 – 2:05:35

Gentleman yields back, I recognize the Rehkommender uh member Mrs. Ramirez for five minutes.

Rep. Ramirez (IL-3)2:05:36 – 2:07:15

Thank you Chairman. Well this is certainly a really critical conversation, I just wanna thank our witnesses for being here and the work that you're doing. The cost of keeping up with the growing cyber attacks and the threats that we see every single day. while as mister jain was uh sharing um these technologies continue to advance at rates that we didn't even imagine a year ago mean that you're gonna need more resources to do so and as you've heard from both sides here as we've had this discussion today the reality is that um we don't wanna talk about funding but we need funding in order to be able to do this work and so i do think it's really important for us to uh make the connections between what level of funding we need and what it's actually going to do. Uh, because I think that for our colleagues, as we leave this committee and talk to our colleagues, um, within our co- within Congress, it's important for them to understand clearly what this additional funding would do, and how it would actually expand your structures in order to provide the protections necessary. So, I wanna in some ways follow up to what, um, Congressman Latreau and I think others have have brought back here. Mr. Harvey, Mister Ahern and Mister Sponholz, what would your state's priorities be if provided additional, not cuts, because we just talked about the reductions that you weren't aware of, but if you were able to receive additional state and local cyber security grants, what level of funding would you be able to make in meaningful improvement improvement to your cyber security? And I'll start with you, cuz ladies first.

Kristin Darby (Witness)2:07:16 – 2:07:30

Thank you. So, I would say, um, it's hard to put an exact number on it because I think the, what I would say is in our previous grant process, which was twenty-one million of federal funds and the state matched six point eight,

Rep. Ramirez (IL-3)2:07:30 – 2:07:31

Mm-hmm.

Kristin Darby (Witness)2:07:31 – 2:07:39

bringing us, uh, roughly to twenty-eight million for that grant, my would say we could have spent four times that. I do think

Rep. Ramirez (IL-3)2:07:38 – 2:07:41

Tell me about meaningful improvements and maybe specifics.

Kristin Darby (Witness)2:07:41 – 2:07:50

Yes. So, so, specifically in the future, the the approaches that we took, while are still grounded and effective today,

Rep. Ramirez (IL-3)2:07:47 – 2:07:47

Mm-hmm.

Kristin Darby (Witness)2:07:50 – 2:08:00

I think have to pivot to an AI enabled world. And so part of that may be workforce expansion, part of it may be uh digital agent expansion,

Rep. Ramirez (IL-3)2:08:00 – 2:08:00

Mm-hmm.

Kristin Darby (Witness)2:08:00 – 2:08:37

because that is what our adversaries will be leveraging. And so the ability to have the flexibility to understand what is needed this year, may be different than next year, based on the exponential rate of change. So that flexibility is gonna be important, but also the capability to be able to attract the appropriate level of talent and expertise to be able to identify those scalable s uh solutions. The pace of change uh i is here and things um are rapid. We need um agent-enabled solutions that are scalable.

Rep. Ramirez (IL-3)2:08:37 – 2:08:37

Mm-hmm.

Kristin Darby (Witness)2:08:37 – 2:08:44

And so um uh anomalies both for internal threats and external threats

Rep. Ramirez (IL-3)2:08:43 – 2:08:43

mmm

Kristin Darby (Witness)2:08:44 – 2:08:50

need to be able to be detected and we need to be able to rapidly respond twenty four by seven

Rep. Ramirez (IL-3)2:08:48 – 2:08:49

mmm

Kristin Darby (Witness)2:08:50 – 2:08:54

um so those are the areas of focus that we would look for

Rep. Ramirez (IL-3)2:08:53 – 2:08:54

yeah it's really helpful

Kristin Darby (Witness)2:08:55 – 2:09:00

uh related to the emerging risks that we are facing currently thank you

Rep. Ramirez (IL-3)2:09:00 – 2:09:02

thank you miss miss darby mr ahern

Colin Ahern (Witness)2:09:02 – 2:09:44

i think three things ma'am number one is defensibility number two is resilience and number three is legacy technology With regards to defensibility, shared services that are easy to consume, that are delivered by top-tier uh enterprise technology partners, things like multi-factor authentication, like network defenses like we've heard. Mm-hmm. Number two, resilience. We know bad things are gonna happen, so having backups, cloud-based backups, business continuity planning and other things are very, very important. And with regards to legacy technology, these are systems that have been built over multiple decades by multiple vendors, Mm-hmm. uh and if something is old it is harder to secure it is harder to maintain uh and if something's not reliable it doesn't matter if it's secure

Rep. Ramirez (IL-3)2:09:44 – 2:09:44

mmm

Colin Ahern (Witness)2:09:44 – 2:09:49

and obviously if something isn't secured you know it doesn't matter if it's reliable uh and so when the

Rep. Ramirez (IL-3)2:09:48 – 2:09:48

yeah

Colin Ahern (Witness)2:09:50 – 2:10:13

technology debt that we have i think we're gonna be under a margin call uh if you'll excuse the finance metaphor because this technology debt is gonna come due with these ai threats and the you know ever increasing um you know scope of our adversaries Uh, so, you know, I believe that these three things are the things that we all need to do. And obviously, underpinning all of this is falling in love with the basics every single day.

Rep. Ramirez (IL-3)2:10:13 – 2:10:14

Yeah.

Colin Ahern (Witness)2:10:14 – 2:10:19

That's, this is a services business and these services are delivered by, with, and through technology.

Rep. Ramirez (IL-3)2:10:19 – 2:10:23

Yeah. Thank you, Mister Aaron, anything else that you wanna add, Mister Sponholz?

Warren Sponholtz (Witness)2:10:24 – 2:10:33

I'll just say super briefly that um whenever we get a incident in the state, it's usually because we left a door or window open, we've got some sort of vulnerability that should have been taken care of.

Rep. Ramirez (IL-3)2:10:30 – 2:10:31

Mm-hmm.

Warren Sponholtz (Witness)2:10:33 – 2:10:49

So using some of these technologies to better identify the critical vulnerabilities that can really cause a big problem is imperative and then providing the support to the locals to be able to remediate those quickly uh so we won't have another incident uh as a pathway to just better um continuity of services.

Rep. Ramirez (IL-3)2:10:50 – 2:11:06

I really appreciate that. I think as we are looking to reauthorize the state and local cyber s cyber security grant program hearing these specifics from all of you are really critical, uh in order to insure that we do so. providing you the resources necessary to do your work. So thank you and with that I yield back.

Rep. Ogles (TN-5)2:11:06 – 2:11:09

Gentlewoman yields back. I go to the gentleman from California, Mr. Fong.

Rep. Fong (CA-20)2:11:10 – 2:11:54

Uh thank you for the second round. Um as I wanted to follow up on on on the workforce uh issue that I I just mentioned earlier um I'm working with my community college to set up um a certificate program uh to um allow uh our students to c to go into the cyber security um uh industry and and world. um we've had hearings in the past about how there's just a challenge and and as we mentioned before uh the rural communities uh definitely uh have uh have uh uh uh a more uh challenging uh need when it comes to workforce i'm curious uh if you could share uh maybe your your work in tennessee or new york or florida about how you how you're addressing the workforce challenge of of those in the cyber security space

Rep. Ogles (TN-5)2:11:57 – 2:11:57

go ahead

Warren Sponholtz (Witness)2:11:59 – 2:12:30

A quick story from Florida, so uh we spend about thirty five million dollars a year on a education workforce development program to be able to provide uh certifications, uh training, tabletops, um lots of different cyber security related uh education opportunities for all public uh employees whether it's education state local across the board. Um, see had a lot of great participation with that, uh and that's been effective to be able to upskill um the workforce around the state um have us better prepared

Colin Ahern (Witness)2:12:31 – 2:13:30

uh i think a couple of things number one is we have a deep and long-standing relationship with our community colleges uh we have numerous cyber clinics across the state including several that are part of the national security agency cyber clinics program which is fantastic i was fortunate enough actually two months ago to be at utica university uh outside of room new york uh where they inaugurated a cyber range which is an avenue in in which both at the associate's and the bachelor's and the graduate level, students and community members can participate in real life cyber exercises but in a safe and controlled environment. Uh and third thing I'd mention, service curriculum, in New York State through our partners in the legislature and our state education department we have a K through twelve computer science for all curriculum which includes cyber bullying, social media awareness, uh banking online, and cyber security best practices. I have two kids in public school and to hear my daughter ask me if my gmail had multifactor warmed my heart, sir.

Kristin Darby (Witness)2:13:33 – 2:15:57

Yes, in uh Tennessee we've taken a multi-prong approach, um so I will start with uh the AI council that the state has. We have this year set up a um two different subcommittees, one focused specifically on uh education, which is both K through twelve and higher ed. And part of that focus is not only um cyber security, but also AI education and the convergence of both. Um, so focusing on bringing practical applied learning solutions to individuals and leveraging vocational, uh, schools that exist across the state. We are also um focusing on workforce development. So how do we start to proactively develop programs around uh particular job areas that we expect may s- uh have disruption, how do we upskill and transition uh employees and workforces to be readied for the future and the expectations of those roles so there's work groups focusing on that um we have also through grants supported um innovation schools and so we have a high school in Williamson County that's actually opening in August that is a um, I I think will is well positioned to be a national landmark of um vocational schools, but one of the areas of focus is AI and cyber security. So through dual enrollment with um Tennessee universities, they will um graduate from high school with certifications where they are employable at the day of educa- of uh graduation. And then at the state we have um a cyber security internship program. And so we are on our third year with that program, but have seen great success where the um graduates of our program, after they have completed their college education, have a hundred percent been employable in the cyber security field, with um employers in Tennessee or nationally. And then the last, I would just say there was a question earlier is, are any of the states working with the Department of Energy? So we are blessed to have Oak Ridge National Lab. as a asset within the state of Tennessee. Uh, we have a very strong partnership with them. They also serve on the AI council and are active, uh, participants in many of the programs that I just mentioned.

Rep. Fong (CA-20)2:15:58 – 2:16:19

Uh, thank you very much. I I think there's a a lot of best practices I think I've heard. Um, maybe w- uh, I know the chairman and I have talked about our community colleges and and and how we uh can enhance those pathways and so on. Maybe we can uh have a further a further discussion about uh how we uh address this and go, you know, learn uh from my state of California how we can learn from you and vice versa. Thank you very much. Yeah, Mr. Chairman, I yield back.

Rep. Ogles (TN-5)2:16:20 – 2:17:51

Gentleman yields back and as we're closing out and I do I do we we got the both you gentlemen had some closing remarks we'll get to you. I I do wanna just touch on the the recent NAS CIO Deloitte survey talking about workforce. Uh, and your margin call, sir, shows that only one in five states CISOs believes their cyber workforce has the skills to meet the threats that they're facing. And then that's, which is just a sh- that's a huge drop from just two years ago. And then a- additionally that NASCIO Deloitte survey found that state CISO confidence in protecting state information assets has dropped by more than half in four years and that zero state CISOs are very confident in the cyber security practices of their local local governments which somewhat touches on this Darby on this idea of digital agents uh in protecting one's infrastructure. And so part of my question as you, as the two of you, each of you close out, is when you think about that toolbox, that uh, you know, it essentially needs to be created in coordination with the federal government, with some of our state leaders and agencies and nonprofits, et cetera, um, is do you see those agents being created by us? Are we partnering with, you know, Grok or whomever? But then again, we're housing it so we can share it, cuz it's gotta be easily consumable, right? Click it and deploy it. Because again, Bill, who's a fantastic guy, am- amazing American, great at his job, he's also one guy. Mister Hearn.

Colin Ahern (Witness)2:17:52 – 2:18:56

I think it's a great point, sir. And I think we need to um think laterally with regards to how we're approaching these problems, because one of the other things that we're seeing is in addition to this continued you know the water continuing to boil ever faster uh we're seeing the um you know the collapse of deterrence as you mentioned sir when you want with an individual on a laptop can have the same capability as the MSS uh you know that fundamentally changes how we as a government as a people as a civil society need to think about these risks uh so things like infrastructure as code, using vendor best practices Obviously we talked about some of the enhancements to the operationalization of the grant program. These I think are all part of a story where how we deliver these services is not gonna look like you said five years from now like it looked five years before. And that's both because the expectations of our citizens are changing, but also because the risk that these systems are facing are changing so fundamentally and changing so quickly.

Kristin Darby (Witness)2:18:58 – 2:21:24

Yes, um, so in closing I would say preventative, not reactive. is really the theme that Tennessee has adopted. And we've discussed here that the the pace of change has exponentially um shifted, and we're seeing increasingly sophisticated adversaries leveraging automation and artificial intelligence to accelerate attacks and reduce time available for defenders to respond. So Tennessee plans to continue to build on the whole of state approach in the improvements that we have made which were nineteen point two percent maturity over the last three years that we have reported. With that, we also need um to continue to partner with private sector. We also uh meet regularly with our model partners uh around how do we get AI agents, um created in ways that will help us accelerate. So from Tennessee's approach, we think it's a mix of partnering with the private sector, to ensure that they have solutions within the tools that we use that can be rapidly deployed to continue to keep state assets and our communities and our private entities protected. The other element is we recognize within the state, but also many of our private um organizations that operate within the state of Tennessee also have their own proprietary solutions and architectures and will be building their own agents. We need access from a model perspective to be able to also respond, not just rely on vendor tools. Um, for those organizations that have that sophistication, and it also better positions Tennessee to be able to help the local communities, municipalities, law enforcement, et cetera, if they have proprietary solutions that are not dependent on private sector uh tools that might be available. So with that, um the last thing I would mention is we talked about um ARG AI governance and and bad actors, do they follow the same rules that we do? And we have positioned ourselves through the AI council as being very focused on AI governance, transparency, and safety. But we recognize that our adversaries don't respect the same rules and do not possess the same values. We must be positioned in Tennessee and across

Rep. Ogles (TN-5)2:21:46 – 2:22:22

I wanna say thank you to all the witnesses for their testimony, uh and and the members for their questions. Members of the subcommittee may have some additional questions for the witnesses, and we would ask witnesses to respond to these in writing, pursuant to committee rule seven E. The hearing record will be open for ten days. Without objection, I'm entering into the record a letter from the Consortium for School Networking dated May eighteenth, twenty twenty six, and a letter from the Software Information Industry Association dated May nineteenth, twenty twenty six. And as they are about to call votes without objection, this committee uh this subcommittee stands adjourned.

Morning digest

Start every morning briefed on yesterday’s hearings

A free weekday email covering yesterday’s hearings and transcripts newly unlocked in the archive.

Free weekday email. Unsubscribe anytime.